Overview
- Symantec and Broadcom researchers published linked reports on Aug. 13, 2026 documenting that Jewelbug runs both government espionage and crypto‑fraud campaigns from the same XG‑Web control panel.
- XG‑Web logged more than one million implant check‑ins and enabled exfiltration of over 580,000 browser cookies and more than 2,300 email bodies, giving operators persistent access to government accounts and services.
- The group’s toolkit includes the Antino Windows backdoor, a Linux/router implant (ClientKing), and a malicious browser extension that silently swaps copied cryptocurrency wallet addresses to attacker accounts.
- Fraud operations used AI to generate thousands of fake exchange downloads and hundreds of lookalike domains, amplified by SEO poisoning so Chinese‑speaking users searching for exchanges were routed to malicious sites.
- Researchers say a small, role‑based operator team managed both lines of work from the same backend, a structure that raises risks to diplomats, government services and ordinary crypto users and could enable long‑term data theft.