Meet Jewelbug: The Chinese Hacker-for-Hire Group Stealing Crypto and Spying on Governments at the Same Time
A single criminal outfit is running a massive cryptocurrency scam network with one hand and breaking into Middle Eastern government email systems with the other. Researchers say the group almost certainly works for China.

Key points
- Symantec researchers identified a Chinese hacker-for-hire group called "Jewelbug" that runs both state-sponsored espionage and mass cryptocurrency fraud from a single control panel.
- Jewelbug's fake cryptocurrency exchange network spans hundreds of sites managed by 44 content servers, with over 580,000 stolen browser sessions found in its systems.
- The group broke into a state-owned telecoms platform in the Middle East and silently infected every government employee who logged in to check their email.
- Jewelbug's most dangerous tool is a fake browser extension called "PDF Viewer" that can read everything a victim does online and silently swap out cryptocurrency wallet addresses during transactions.
- No direct proof ties Jewelbug to the Chinese government, but Symantec's lead analyst says no other explanation fits the targeting.
A Chinese criminal group is pulling off two very different jobs at once, and doing both well. On one side, it runs hundreds of fake cryptocurrency websites designed to steal money from ordinary people. On the other, it breaks into government agencies, military networks, and telecoms companies across Asia and the Middle East. Symantec, the cybersecurity company, published research this week identifying the group as "Jewelbug" and first reported by Dark Reading.
"This is quite different to cases where we've seen state-sponsored actors dabbling in cybercrime to make a little extra money," said Dick O'Brien, principal intelligence analyst at Symantec's Threat Hunter Team. "The sheer scale of the fraud business is the biggest clue."
How does Jewelbug actually break in?
Jewelbug's most dangerous trick is a fake browser extension (a small add-on program that runs inside your web browser) called "PDF Viewer." It does not view PDFs. Instead, it requests every permission the browser allows, then silently steals cookies (small files that keep you logged into websites), passwords, browsing history, screenshots, and live web traffic. It can also swap out a victim's cryptocurrency wallet address during a transaction, replacing it with the attacker's own address, though Symantec says this feature has not been used yet.
For government targets, Jewelbug found a smarter route than attacking each agency separately. The group broke into a shared web-hosting platform run by a Middle Eastern country's state telecoms provider. Every time a government employee logged in to check their email, a hidden script automatically registered them in Jewelbug's control panel, stole their login session, and showed them a fake Adobe Flash update prompt hiding two pieces of malware.
| Tool | Type | Purpose |
|---|---|---|
| Antino | Windows backdoor (hidden remote-access program) | Espionage on government and military targets |
| ClientKing | Linux backdoor | Espionage, mainly on servers |
| PDF Viewer | Fake browser extension | Steals data, can hijack crypto transactions |
| XG-Web | Criminal control panel | Manages all infections and stolen data |
Should ordinary people be worried?
Yes, particularly anyone who uses cryptocurrency or searches for trading platforms online. Jewelbug uses artificial intelligence to generate thousands of fake crypto, sports-betting, and finance websites, then uses automated bots to push those fake sites up search engine rankings so real people find them first.
Symantec found more than 580,000 stolen browser sessions and several thousand sets of login credentials sitting in Jewelbug's systems. If you use a lesser-known cryptocurrency exchange, double-check it is a legitimate service before entering any account details.
O'Brien is direct about the China link: "Given their location and their targeting, by far the most likely scenario is that they are working for China." He acknowledges there is no hard documentary proof, but says spying for any other government would carry far greater risk for a China-based group.
For defenders, the Jewelbug case is a reminder that browser extensions are a genuine attack surface. Organisations should audit which extensions staff are allowed to install, and treat unsolicited "Flash update" prompts (or any unexpected software pop-up) as an immediate red flag.



