Hackers breach govt webmail while running parallel crypto fraud
China-linked Jewelbug group compromised webmail for 15 government tenants while running industrial-scale cryptocurrency fraud from the same control panel, researchers at Symantec found.
Intelligence analysis by Llama

Symantec researchers say the China-based Jewelbug (Earth Alux/REF7707) used one shared control panel to run government webmail espionage across the Middle East and Southeast Asia alongside AI-driven crypto exchange fraud impersonating OKX and Binance.
Bad guys in China broke into government email systems to spy on them, and at the same time they ran fake crypto trading websites to steal people's money. They used sneaky popups that looked like normal software updates to plant bad programs on computers, and used robots to push their scam sites to the top of search results.
Analysis
15 government webmail tenants
The campaign's most striking element is the reach of a single foothold. By compromising a shared web-hosting platform operated by a state telecommunications provider and national services agency, Jewelbug obtained write access to the common template and inserted one script tag. That single hook fired on the login page and every mailbox view across 15 government tenants and nine domains. Runtime server logs recorded roughly 1.1 million geolocation events against approximately 4,300 distinct source IP addresses, with the bulk of activity targeting a Southeast Asian country's state telecom and military networks, a Middle Eastern country's national carrier ranges, and a second Southeast Asian country's government ministry infrastructure. The efficiency of this approach is the warning: a shared service in government IT is a force multiplier for any attacker who lands on the underlying platform.
Antino and XG-Web
The malware toolkit reveals a mature, dual-purpose operation. Antino, the main Windows backdoor, is delivered through malicious HTA files and fake Adobe Flash or Adobe installers, then drops a Chrome and Firefox extension called PDF Viewer that steals cookies and credentials, intercepts traffic, injects JavaScript, and exposes browser functions. A second framework, XG-Web, handles remote access and victim management, and the same control panel ties espionage to fraud. The researchers also found a Rust-based implant called ClientKing aimed at Linux servers, ARM64 devices, and ASUS routers, with support for command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading. Obfuscated payloads staged on public Google Docs let the implants blend in with legitimate Google traffic, complicating detection.
44-server content-management fleet
The financial side is not a side hustle. Symantec observed an automated pipeline that scrapes keywords, generates thousands of AI-written articles, and publishes them across a 44-server content-management fleet and hundreds of lookalike domains impersonating OKX and Binance. Click bots manipulate search rankings to push these pages up the results. Symantec puts high confidence in attributing the financially motivated activity to a Chinese company that advertises SEO services, while the group's victim database holds more than one million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies. The combination of state-grade tradecraft, a monetized SEO front, and a unified C2 makes Jewelbug a case study in how modern threat actors blur the line between cyber-espionage and cyber-crime.
Key points
- China-linked group Jewelbug (Earth Alux/REF7707) used a single compromised webmail template to reach 15 government tenants across nine domains.
- Symantec says the same C2 control panel ran state-aligned espionage and large-scale cryptocurrency fraud impersonating OKX and Binance.
- Toolkit includes the Antino Windows backdoor, the PDF Viewer browser extension, the XG-Web framework, and a Rust-based ClientKing implant for Linux, ARM64, and ASUS routers.
- Symantec recorded roughly 1.1 million geolocation events from about 4,300 source IPs, hitting targets in the Middle East, Southeast Asia, and South Asia.
- The fraud operation uses AI-generated articles, a 44-server content fleet, and click bots, with researchers linking the financial activity to a Chinese SEO services company.
Symantec has published indicators of compromise and a detailed technical report, giving defenders across the affected regions a chance to hunt for the Antino, XG-Web, and ClientKing implants in their environments. The visibility into the shared control panel also means both espionage victims and crypto-fraud targets can be enumerated and warned.
With 580,000 stolen browser cookies and more than 2,300 exfiltrated email bodies already in the group's database, the damage from the espionage side is largely done and may fuel further intrusions. The dual-use infrastructure, including a 44-server content fleet and lookalike crypto domains, can be rebuilt quickly, and the supply-chain foothold on a shared government webmail platform is unlikely to be fully remediated across all 15 tenants in the near term.



