XG-Web is a browser-centric remote-access and information-stealing framework used by Jewelbug. It turns a victim's browser into a full remote-control channel, allowing operators to access the host and internal network. Built with React, Node.js, and MySQL, it uses scheduled jobs to check C&C infrastructure against VirusTotal and leverages Google Docs for payload hosting.