A cyber espionage campaign attributed to the Jewelbug APT group, suspected to be based in China, has been uncovered by the Threat Hunter Team. The group conducts both espionage against Middle Eastern and Asian government sectors and cryptocurrency fraud by using malicious browser extensions and sophisticated malware.
They operate from a single command infrastructure, utilizing tools like the Antino backdoor and ClientKing implant, compromising over 1 million devices while stealing extensive data including cookies and credentials. The operations leverage fake software updates and Google Docs for malicious payload delivery. Analysts have identified links to a Chinese company and have outlined security measures for potential targets to mitigate these threats.