SECURITY researchers from Broadcom's Threat Hunter Team have identified the threat group Jewelbug, associated with Chinese cyber espionage, as a hack-for-hire entity involved in cryptocurrency fraud. Their report reveals that Jewelbug operates on shared infrastructure for both espionage against governmental bodies in the Middle East and Asia, and financially motivated attacks targeting Chinese-speaking cryptocurrency users.
The group's malware, including advanced backdoors and command-and-control systems, allows them to deploy multi-faceted cyber operations effectively, leveraging platforms like Microsoft's services and Google for stealth. The investigation highlights over a million compromised records from government email systems and ongoing operations that intertwine fraud and espionage.