A Chinese hacker-for-hire group called Jewelbug has been running government espionage campaigns and cryptocurrency fraud operations simultaneously, using the same infrastructure for both. Symantec’s Threat Hunter Team published findings revealing the group’s dual-purpose playbook, which combines state-level surveillance tools with fake crypto exchange websites designed to drain wallets.

The scale is striking. Jewelbug’s centralized command-and-control system, called XG-Web, has tracked over one million implant check-ins across its victim database. The group has stolen more than 580,000 browser cookies and exfiltrated over 2,300 email bodies, all while maintaining a relatively small team with role-based access controls.

A spy agency that moonlights in crypto theft

Jewelbug, which also operates under the aliases Earth Alux and REF7707, has been active since mid-2023. Its espionage operations primarily target government entities in the Middle East, Southeast Asia, South Asia, and Taiwan. One campaign involved planting a malicious script across more than 15 government webmail tenants on a shared hosting platform, a technique known as a waterhole attack.

But spying on diplomats is only half the operation. On the financial crime side, the group has registered hundreds of lookalike domains and created thousands of fake downloads for crypto exchanges. These fraudulent sites are generated with AI and primarily target Chinese-speaking victims.