www.darkreading.com 8/13/2026, 10:32:05 AM · external

Jewelbug APT mixes espionage, crypto theft via custom malware

Jewelbug APT mixes espionage, crypto theft via custom malware
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
🇨🇳 REF7707

THE article discusses the **Jewelbug APT** group, a cybercriminal organization believed to be operating from China. This group engages in both state-sponsored cyber espionage and cryptocurrency theft using a single command-and-control panel. Their activities include stealing funds from individuals and compromising government and military networks, particularly in Asia and the Middle East.

The group employs sophisticated tools, including custom malware such as a Windows backdoor (Antino) and a browser extension masquerading as a PDF viewer that collects sensitive information from victims. Jewelbug has successfully targeted numerous high-profile entities, demonstrating the blurred lines between state-sponsored hacking and independent cybercrime.

Researchers speculate that Jewelbug operates under the patronage of the Chinese government, leveraging third-party contractors to enhance their cyber capabilities.

View full article

Article by CyberSIXT