Security researchers from Broadcom’s Threat Hunter Team have revealed that Jewelbug, a threat group associated with Chinese-sponsored cyber espionage operations, may be a hacker-for-hire group that also runs profitable crypto fraud campaigns.
In a new report published on August 13, the threat intelligence team – which brought together experts from Symantec and Carbon Black – shed new light on the advanced persistent threat (APT) group, also known as Ink Dragon, Earth Alux, REF770 and CL-STA-0049.
The researchers revealed that Jewelbug uses the same infrastructure to conduct espionage against governments and militaries across the Middle East, Southeast Asia and South Asia as well as a financially motivated operation targeting Chinese-speaking cryptocurrency users through fake exchange-download portals.
“The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel,” the Broadcom report noted.
At least one of the operators, likely running what Broadcom described as “the commercial arm of the business,” identified as ‘ople500’ in the group’s control panel, has been identified as using the ‘paopaodada’ (‘bubble boss’) persona.
This individual has been advertised on Telegram as the contact for a “website ranking rental” service. Broadcom associated the individual “with high confidence” to a company, described as an SEO business, registered in Changsha, the capital of the Hunan province.
The Threat Hunter Team has identified the name of the sole legal representative of this company and assessed that that person supplies access, infrastructure and delivery to the espionage operation rather than being part of the team of operators.
Cyber Espionage Targets
Jewelbug's cyber espionage operations had already been reported by various threat intelligence teams, including Trend Micro's TrendAI, Palo Alto Networks' Unit 42 and Check Point Research.
Researchers found the actor typically gained access through vulnerable IIS and SharePoint servers before deploying web shells and a sophisticated backdoor tracked as VARGEIT, Squidoor or FinalDraft.
The malware supported multiple covert command-and-control (C2) methods, including Microsoft Graph/Outlook APIs, DNS tunnelling and ICMP tunnelling.
After a months-long investigation into some of the threat group’s operations, Broadcom researchers found it has targeted several government organizations across the Middle East and Southeast Asia, with more than 90 police and government email addresses in South Asia.
They also found a victim database which recorded more than one million implant check-ins and over 580,000 stolen browser cookies in less than three months of active operations.
One set of implants was configured to utilize the internal proxy of a major US aerospace and industrial manufacturer.
In its largest operation, a single planted script placed a watering-hole on more than 15 government webmail tenants in a Middle Eastern country at once.
Crypto Fraud Targets
Meanwhile, some of Jewelbug's infrastructure was used to run a cryptocurrency fraud business on the side.
The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan.
The report added that the common thread across the group's espionage targets was government communications systems and the service providers that host them, potentially providing long-term access to official correspondence.
Jewelbug’s Common Infrastructure for Espionage and Fraud
At the center of both the espionage and cryptocurrency fraud operations was XG-Web, a browser-based C2 platform that acted as the group's central management console.
According to the Broadcom report, the same XG-Web infrastructure was used to administer victims from both campaigns, with implants, stolen data and operator activity all feeding into a shared backend database.
One of the primary tools connected to this infrastructure was Antino, the group's Windows backdoor.
Antino communicated with operators through the Microsoft Graph API, allowing C2 traffic to blend in with legitimate Microsoft cloud services.
The Broadcom report said the malware was used across multiple Jewelbug campaigns and was deployed through fake software installers and themed lures.
The group also operated a malicious Chrome and Firefox extension called ‘PDF Viewer,’ which was paired with a helper program disguised as a Microsoft Edge component. The combination gave operators extensive access to victims' browsers, enabling them to steal cookies, credentials and browsing data, while also providing a command shell on the compromised host through a native messaging component.
Alongside Antino, Jewelbug used a Linux and router implant known as ClientKing, which supported multiple C2 methods, including DNS tunnelling and provided remote shell access and pivoting capabilities.
The researchers noted that ClientKing infrastructure overlapped with the group's wider XG-Web ecosystem, further linking the espionage and fraud operations.
Finally, the group also abused Google Docs for payload delivery and C2. When operators launched a campaign, the backend created public Google documents containing obfuscated payloads, which implants would retrieve and execute. By leveraging Google's infrastructure, the group was able to disguise malicious activity as legitimate traffic and reduce the likelihood of detection.










