CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

August 14, 2026

The China-linked threat actor known as Jewelbug has been observed conducting cyber espionage against governments and militaries while simultaneously running a cryptocurrency fraud operation. According to Broadcom’s Symantec and Carbon Black Threat Hunter Team, both missions are administered from a single control panel called XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim’s browser into a full remote-control channel.

Jewelbug is assessed to be a China-based hackers-for-hire group that runs parallel operations, including espionage against governments in the Middle East, Southeast Asia, and South Asia, and a for-profit cryptocurrency fraud business targeting Chinese-speaking victims. The group has developed five generations of command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers, and network devices, all feeding a single database of victims.

The primary implant is a malicious browser extension named “PDF Viewer” that runs on Chrome and Firefox, requesting dangerous permissions to access cookies, run scripts, intercept web requests, and harvest credentials. It also includes a clipboard clipper that swaps cryptocurrency wallet addresses to reroute transactions. To escape the browser sandbox, the extension uses a Windows helper registered as a native-messaging host under the misleading name com.microsoft.runedge.

Other tools in Jewelbug’s arsenal include Antino, a Windows backdoor delivered via malicious HTML Application (HTA) downloaders and using Microsoft Graph API for C&C; and ClientKing, a Rust implant targeting Linux servers and routers with five C&C channels, including a DNS tunnel. The group also uses a kernel-module rootkit and a malicious authentication module to steal credentials from su and sudo.

In what is described as the largest espionage operation by the threat actor, a web hosting provider was compromised to inject JavaScript into a webmail installation used by multiple ministries of a Middle Eastern government. The watering hole campaign spanned 15 government webmail tenants, exfiltrating cookies and serving a next-stage payload that displayed a fake Adobe Flash update prompt. Victims who clicked received Antino and the “PDF Viewer” extension.

The scale of the espionage campaign is vast, with over one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and at least 2,300 exfiltrated email bodies. Runtime logs recorded roughly 1.1 million geolocation events against about 4,300 distinct source IP addresses.

The financial arm of Jewelbug operates as a registered Chinese company advertising SEO services on Telegram, but it is a front for an SEO poisoning scheme using AI-generated fake pages impersonating OKX and Binance, over 40 content management servers, and click fraud bots.

Jewelbug overlaps with threat clusters tracked as CL-STA-0049 (Palo Alto Networks Unit 42), Earth Alux (Trend Micro), and REF7707 (Elastic Security Labs). In October 2025, the group was attributed to a five-month-long intrusion against a Russian IT service provider.

Attack groups: Jewelbug, CL-STA-0049, Earth Alux, REF7707

Malware: XG-Web, PDF Viewer, Antino, ClientKing

Companies: Broadcom, Symantec, Carbon Black, Palo Alto Networks, Trend Micro, Elastic Security

Products: Microsoft Graph API, VirusTotal, Google Docs, Google Fonts