
RESEARCHERS have linked a Chinese hack‑for‑hire outfit called Jewelbug to a campaign that mixes state‑sponsored espionage with cryptocurrency fraud. The finding comes from Broadcom's Threat Hunter Team, which identified the group as operating on shared infrastructure for both government targets and crypto‑theft.
Jewelbug deploys a Windows backdoor known as Antino and a malicious browser extension that masquerades as a PDF viewer to harvest credentials. The tools are hosted on legitimate cloud platforms such as Microsoft services and Google infrastructure, allowing the attackers to blend with normal traffic. Analysis of the malware shows no associated CVE identifiers, indicating reliance on bespoke code rather than known vulnerabilities.
Activity was first observed on 13 August 2026 and continued through the following day, with the group targeting governmental bodies across the Middle East and Asia. In addition to stealing sensitive communications, Jewelbug has compromised more than a million email records from those administrations. Financially motivated operations focus on Chinese‑speaking cryptocurrency users, draining wallets through credential theft and fraudulent transactions.
The group is described as a hack‑for‑hire entity that operates under the direction of Chinese interests while also pursuing its own profit motives. Researchers assign the tracking reference REF7707 to Jewelbug and note its dual use of espionage tools and crypto‑theft infrastructure. This blending of state and criminal objectives makes attribution harder and increases the risk to both public and private sectors.
Defenders should monitor outbound connections to unfamiliar cloud service endpoints, especially those mimicking legitimate Microsoft or Google domains. Application control policies that block unsigned browser extensions can prevent the malicious PDF viewer from being installed. Endpoint detection and response rules should look for the Antino backdoor's characteristic registry changes and file‑less execution patterns. Sharing identified command‑and‑control indicators with threat‑intelligence platforms helps block the infrastructure at the network edge.
Organisations are encouraged to run regular hunts for DLL side‑loading and suspicious PowerShell scripts that may indicate post‑exploitation activity. User awareness training must emphasise the risks of granting permissions to unknown extensions and of clicking links in unsolicited messages. By combining technical controls with vigilant staff, the hybrid threat posed by Jewelbug can be reduced.