securityonline.info 8/20/2026, 8:10:59 AM · external

Jewelbug APT uses fake updates to spy on governments

Jewelbug APT uses fake updates to spy on governments
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
🇨🇳 REF7707

A cyber espionage campaign attributed to the Jewelbug APT group, suspected to be based in China, has been uncovered by the Threat Hunter Team. The group conducts both espionage against Middle Eastern and Asian government sectors and cryptocurrency fraud by using malicious browser extensions and sophisticated malware.

They operate from a single command infrastructure, utilizing tools like the Antino backdoor and ClientKing implant, compromising over 1 million devices while stealing extensive data including cookies and credentials. The operations leverage fake software updates and Google Docs for malicious payload delivery. Analysts have identified links to a Chinese company and have outlined security measures for potential targets to mitigate these threats.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline