Meet Jewelbug: The Chinese Hacker-for-Hire Group Stealing Crypto and Spying on Governments at the Same Time

A single criminal outfit runs a massive cryptocurrency scam network with one hand and breaks into Middle Eastern government email systems with the other. Researchers say the group almost certainly works for China.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Split-screen digital representation showing cryptocurrency exchange data on one side and government email infrastructure on the other, both displaying intrusion
Share

Key points

  • Symantec researchers identified a Chinese hacker-for-hire group called "Jewelbug" that runs state-sponsored espionage and mass cryptocurrency fraud from a single control panel.
  • Jewelbug's fake cryptocurrency exchange network spans hundreds of sites managed by 44 content servers, with over 580,000 stolen browser sessions found in its systems.
  • The group broke into a state-owned telecoms platform in the Middle East and silently infected every government employee who logged in to check their email.
  • Jewelbug's most dangerous tool is a fake browser extension called "PDF Viewer" that reads everything a victim does online and can silently swap out cryptocurrency wallet addresses during transactions.
  • No direct proof ties Jewelbug to the Chinese government, but Symantec's lead analyst says no other explanation fits the targeting.

A Chinese criminal group is pulling off two very different jobs at once, doing both well. It runs hundreds of fake cryptocurrency websites designed to steal money from ordinary people. It also breaks into government agencies and telecoms companies across Asia and the Middle East. Symantec published research this week identifying the group as "Jewelbug," first reported by Dark Reading. The tradecraft fits a pattern we've tracked since July: our 27 July story covered China-linked hackers deploying fresh spyware against Middle East government networks.

"This is quite different to cases where we've seen state-sponsored actors dabbling in cybercrime to make a little extra money," said Dick O'Brien, principal intelligence analyst at Symantec's Threat Hunter Team. "The sheer scale of the fraud business is the biggest clue."

How does Jewelbug actually break in?

Jewelbug's sharpest instrument is a fake browser extension (a small add-on program that runs inside your web browser) called "PDF Viewer." It does not view PDFs. It requests every permission the browser allows, then steals cookies (small files that keep you logged into websites), passwords, browsing history, and live web traffic. It can also swap out a victim's cryptocurrency wallet address mid-transaction, replacing it with the attacker's own, though Symantec says this feature hasn't been used yet. The extension also lets attackers inject arbitrary code into any webpage, or operate the victim's browser as if they were sitting at the keyboard themselves.

For government targets, Jewelbug found a smarter route than attacking each agency separately. The group broke into a shared web-hosting platform run by a Middle Eastern country's state telecoms provider. Every time a government employee logged in to check email, a hidden script registered them in Jewelbug's control panel, stole their login session, and presented a fake Adobe Flash update prompt concealing two pieces of malware.

Tool Type Purpose
Antino Windows backdoor (hidden remote-access program) Espionage on government and military targets
ClientKing Linux backdoor Espionage, mainly on servers
PDF Viewer Fake browser extension Steals data, can hijack crypto transactions
XG-Web Criminal control panel Manages all infections and stolen data

Should ordinary people be worried?

Yes, particularly anyone who uses cryptocurrency or searches for trading platforms online. Jewelbug uses artificial intelligence to generate thousands of fake crypto and sports-betting websites, then uses automated bots to push those fake sites up search engine rankings so real people find them first.

Symantec found more than 580,000 stolen browser sessions, 2,300 fully copied email bodies, and several thousand login credentials in Jewelbug's systems. If you use a lesser-known cryptocurrency exchange, verify it's a legitimate service before entering any account details.

O'Brien is direct about the China link: "Given their location and their targeting, by far the most likely scenario is that they are working for China." He acknowledges there's no hard documentary proof, but says spying for any other government would be a far riskier proposition for a China-based group. He also notes that using contractors gives nation-states plausible deniability, at the cost of operational control: "Their operational security also tends to be a lot poorer, as evidenced by Jewelbug, who left a trail of evidence behind them."

For defenders, the Jewelbug case confirms that browser extensions are a genuine attack surface. Audit which extensions staff can install, and treat any unexpected software pop-up as an immediate red flag.

© 2026 Threat Vectr