Chinese hacker crew Jewelbug just got fully doxxed running a dual op:
→ Cyber espionage hitting Middle East/SEA/South Asia gov + military targets
→ Crypto phishing scam targeting Chinese users
Both ops run off the SAME control panel (XG-Web). Symantec tracked them for months:
• 1M+ malware check-ins in <3 months
• 580K+ stolen browser cookies
• Linked to a Hunan-registered company via operator ID docs
• Legal rep identified
Their toolkit: Antino backdoor + fake PDF Viewer browser extension. They waterholed 15+ gov email tenants in one Middle East op alone.
Scam side? Changsha company advertising "website ranking rental" on Telegram. AI-generated fake exchange sites, hundreds of domains mimicking $OKX and Binance.
Researchers think the scam biz funds + provides infrastructure access for the espionage ops. Same infra, same panel, same crew.
This is what state-adjacent hacking looks like in 2025. Stay paranoid with browser extensions and always verify URLs.
→ Cyber espionage hitting Middle East/SEA/South Asia gov + military targets
→ Crypto phishing scam targeting Chinese users
Both ops run off the SAME control panel (XG-Web). Symantec tracked them for months:
• 1M+ malware check-ins in <3 months
• 580K+ stolen browser cookies
• Linked to a Hunan-registered company via operator ID docs
• Legal rep identified
Their toolkit: Antino backdoor + fake PDF Viewer browser extension. They waterholed 15+ gov email tenants in one Middle East op alone.
Scam side? Changsha company advertising "website ranking rental" on Telegram. AI-generated fake exchange sites, hundreds of domains mimicking $OKX and Binance.
Researchers think the scam biz funds + provides infrastructure access for the espionage ops. Same infra, same panel, same crew.
This is what state-adjacent hacking looks like in 2025. Stay paranoid with browser extensions and always verify URLs.