Actor Profile

Jewelbug (also tracked as Earth Alux and REF7707) is a China-based threat actor conducting parallel espionage and financially-motivated operations. The group targets government and military entities across the Middle East, Southeast Asia, and South Asia while simultaneously running industrial-scale cryptocurrency fraud. Symantec attributes the financially-motivated activities with high confidence to a Chinese company advertising SEO services. The dual-track operations suggest Jewelbug may function as a hack-for-hire group seeking to profit from cybercrime alongside state-aligned intelligence collection. The actor's infrastructure reveals over one million implant check-ins, 580,000+ stolen browser cookies, thousands of credentials, and 2,300+ exfiltrated email bodies.

TTPs (Tactics, Techniques, Procedures)

Jewelbug compromised a shared web-hosting platform operated by a state telecommunications provider to gain write access to government webmail installations. The actor injected malicious JavaScript into common templates, establishing WebSocket connections to C2 infrastructure for cookie exfiltration and user profiling. Initial access leverages fake Adobe Flash update prompts delivering the Antino backdoor via malicious HTA files and fake installers. The group deploys malicious browser extensions (PDF Viewer) for Chrome and Firefox to steal credentials, intercept traffic, and inject JavaScript. Additional tooling includes the XG-Web remote-access framework for campaign management and ClientKing, a Rust-based implant targeting Linux servers, ARM64 devices, and ASUS routers with capabilities for command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading. The actor uses public Google Docs to host obfuscated payloads, blending malicious traffic with legitimate services. Cryptocurrency fraud operations employ AI-generated content, click-fraud bots for search ranking manipulation, and a 44-server content-management fleet hosting fake exchange sites impersonating OKX and Binance.

Targets & Patterns

Jewelbug primarily targets government and military organizations across the Middle East, Southeast Asia, and South Asia. Critical sectors include defense, telecommunications, education, and aviation. In one campaign, the actor compromised webmail accounts for 15 government tenants in a Middle Eastern country. Server logs recorded approximately 1.1 million geolocation events from 4,300 distinct IP addresses, including 87,200 connections from a Southeast Asian country targeting state telecom and military networks, 53,100 from a Middle Eastern country across national carrier ranges (including Starlink-connected addresses in the capital), and 15,000 from a second Southeast Asian country including government ministry infrastructure. The targeting pattern suggests intelligence collection priorities aligned with Chinese state interests, while the parallel cryptocurrency fraud targets general internet users through fake exchange sites, sports betting lures, pirated livestream portals, and private detective scams.

Historical Context

Jewelbug has been tracked under multiple aliases including Earth Alux and REF7707. The recent webmail compromise campaign represents a continuation of the group's established pattern of targeting government entities while maintaining parallel financially-motivated operations. Symantec's visibility into Jewelbug's C2 management platform, database, server logs, source code, and operator files revealed the scale of operations: over one million implant check-in rows accumulated over time, indicating sustained long-term activity. The dual-track approach—combining espionage with cryptocurrency fraud—appears to be a consistent operational model rather than a recent pivot, with both activities managed from the same control panel infrastructure.

Defensive Recommendations

  • Monitor for unauthorized modifications to shared web-hosting platforms and webmail templates, particularly script injections that establish WebSocket connections to external domains
  • Implement browser extension allowlisting and monitor for suspicious extensions like PDF Viewer that request excessive permissions for cookie access, traffic interception, and JavaScript injection capabilities
  • Detect malicious HTA file execution and fake software installer activity, particularly those masquerading as Adobe Flash or Adobe Reader updates
  • Monitor for unusual outbound connections to public Google Docs used as payload hosting infrastructure, and correlate with process execution patterns indicative of obfuscated payload retrieval
  • Implement network segmentation and monitor for ClientKing implant indicators on Linux servers, ARM64 devices, and ASUS routers, including SOCKS proxy activity, DNS tunneling, and in-memory kernel module loading attempts