Close Menu
NCIJ Network NCIJ Network
    What's Hot

    A mine polluted a Zambian river in 2025: Residents continue to live with the impacts

    August 14, 2026

    North Korea fumes over upcoming US-South Korea military drills | Military News

    August 14, 2026

    The job Zelenskyy can’t fill: Ukraine’s envoy to Trump’s Washington  – POLITICO

    August 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • A mine polluted a Zambian river in 2025: Residents continue to live with the impacts
    • North Korea fumes over upcoming US-South Korea military drills | Military News
    • The job Zelenskyy can’t fill: Ukraine’s envoy to Trump’s Washington  – POLITICO
    • Farage’s by-election victory won’t stop questions about finances
    • JPMorgan debanked Polymarket over regulatory concerns
    • Babbel Promo Code: Up to 65% Off in August 2026
    • Meet Needle 2: An Open 45M-Parameter Tool-Calling Model That Ships as a 14MB Binary and Runs a Full Session in 28MB of RAM
    • Hackers breach govt webmail while running parallel crypto fraud
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers breach govt webmail while running parallel crypto fraud

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 14, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud.

    Although the threat actor has targeted government agencies and organizations in critical sectors, including defense, telecommunications, education, and aviation, its cryptocurrency-related activity suggests that they may also operate as a hack-for-hire group that seeks to profit from cybercrime.

    In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.

    image

    Researchers at Symantec found that the espionage campaign and the cryptocurrency fraud were conducted from the same control panel.

    The China-based hacker group gained write access to the shared webmail installation and inserted a malicious script into its common template. The script then ran on login pages and mailbox views across 15 tenants.

    The webmail attack chain
    The webmail attack chain
    Source: Symantec

    After execution, the script established a WebSocket connection to the attacker’s command-and-control (C2) server, exfiltrated webmail cookies, and retrieved the user’s email address to determine whether it belonged to a targeted government domain.

    Valuable targets would receive a fake Adobe Flash update prompt, which installs the main payload on Windows, the Antino backdoor, and browser tooling.

    Apart from Antino, the threat actor also uses the XG-Web remote-access and data-theft framework for managing campaigns and victim information.

    XG-Web panel
    The XG-Web panel
    Source: Symantec

    According to Symantec, Jewelbug delivers Antino through malicious HTA files and fake Adobe Flash/Adobe installers, and then uses it to deploy additional payloads.

    One of the payloads is a malicious browser extension for Chrome and Firefox, named PDF Viewer, which steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser functions.

    The PDF Viewer capabilities
    The PDF Viewer capabilities
    Source: Symantec

    Symantec traced Antino infections to Jewelbug’s infrastructure and then obtained visibility into the group’s C2 management platform, database, server logs, source code, and operator files.

    The data showed that the hackers ran a large-scale espionage operation and “an industrial-scale cryptocurrency fraud business.”

    “Jewelbug’s victim database holds more than one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies,” Symantec researchers note.

    Regarding the espionage part, Jewelbug targeted government and military organizations across the Middle East, Southeast Asia, and South Asia.

    “Runtime server logs recorded roughly 1.1 million geolocation events against approximately 4,300 distinct source IP addresses: approximately 87,200 connections from a Southeast Asian country (targeting state telecom and military networks), approximately 53,100 from a Middle Eastern country (across the national carrier’s ranges, including Starlink-connected addresses in the capital), and approximately 15,000 from a second Southeast Asian country (including government ministry infrastructure),” Symantec says.

    The researchers explained that the threat actor obtained write access to the webmail installation used by multiple government ministries and agencies after compromising a shared web-hosting platform operated by the state telecommunications provider and national services agency.

    By injecting a single script tag, the threat actor ensured that the JavaScript payload opened a WebSocket to the C2 every time a user on one of nine government domains logged in.

    “A single campaign spanned more than 15 government webmail tenants, with the hook firing on the login page and every mailbox view,” Symantec says.

    The cryptocurrency theft operations are backed by AI-generated articles driving traffic to fake crypto exchange sites and click-fraud bots that manipulate search rankings.

    Jewelbug's parallel operations
    Jewelbug’s parallel operations
    Source: Symantec

    According to the researchers, the threat actor relies on an automated attack pipeline that scrapes keywords, generates thousands of fake download pages using AI, and publishes them “across a 44-server content-management fleet and hundreds of lookalike domains” impersonating OKX and Binance. Using click bots, Jewelbug manipulates rankings to promote their fraudulent pages.

    The fraud uses other lures, as well: sports betting, pirated livestream portals, and private detective scams.

    Symantec researchers have high confidence attributing Jewelbug’s financially-motivated activities to a Chinese company that advertises SEO services.

    Jewelbug also uses a Rust-based implant called ‘ClientKing’ that targets Linux servers, ARM64 devices, and ASUS routers, and supports command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading.

    The hackers used public Google Docs to host obfuscated payloads retrieved and executed by their implants, helping the malicious traffic blend in with legitimate Google services.

    Symantec published indicators of compromise related to observed Jewelbug activity, as well as a more detailed technical report describing the threat actor’s tooling and tradecraft, their financial operation, and the infrastructure used in attacks.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    breach Crypto fraud govt hackers parallel Running Webmail
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    White House To Host Crypto Industry Execs Next Week: Report

    Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

    Belgium’s eID Authentication Opens Citizen Accounts to RCE

    Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    A mine polluted a Zambian river in 2025: Residents continue to live with the impacts

    August 14, 2026

    North Korea fumes over upcoming US-South Korea military drills | Military News

    August 14, 2026

    The job Zelenskyy can’t fill: Ukraine’s envoy to Trump’s Washington  – POLITICO

    August 14, 2026

    Farage’s by-election victory won’t stop questions about finances

    August 14, 2026
    Latest Posts

    Evacuated villagers in Cairngorms allowed home after wildfire threat lifts | Wildfires

    July 25, 2026

    The Fraternal Order Of Police Supports The Clarity Act.

    July 25, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    A mine polluted a Zambian river in 2025: Residents continue to live with the impacts

    August 14, 2026

    North Korea fumes over upcoming US-South Korea military drills | Military News

    August 14, 2026

    The job Zelenskyy can’t fill: Ukraine’s envoy to Trump’s Washington  – POLITICO

    August 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.