Jewelbug is a China-linked, likely China-based threat actor associated with cyber espionage operations and parallel financially motivated cryptocurrency fraud. It is also tracked as Earth Alux, Ink Dragon, REF7707, and CL-STA-0049. Reporting consistently characterizes the group as a small operatorset or mercenary-style cluster that uses shared infrastructure and tooling for both espionage and criminal activity, with evidence linking at least part of its operations to Hunan Province in China. Jewelbug primarily targets government, military, police, and government communications environments across Asia and the Middle East, with additional activity reported against a South American foreign ministry, a Russian IT service provider, and a major U.S. aerospace and industrial manufacturer. Targeting has also extended to telecommunications and IT services organizations, including service providers that host or support government communications platforms. Decoy material and victimology indicate interest in Taiwan as well. The group is notable for browser-centric intrusion tradecraft built around XG-Web, a custom remote-access and information-stealing platform used to manage implants, stolen data, and operator activity. A hallmark capability is a malicious browser extension masquerading as a PDF viewer for Chrome and Firefox that can steal cookies, credentials, browsing history, bookmarks, screenshots, clipboard contents, and web traffic; inject arbitrary JavaScript into web sessions; and remotely control browser activity. Through a native-messaging helper on Windows, Jewelbug can escape the browser sandbox and execute system commands, enabling broader post-exploitation. This tradecraft supports both credential theft and session hijacking at scale. Jewelbug has also deployed custom malware including the Antino Windows backdoor and the ClientKing Linux and router implant. Antino has been delivered through fake software installers and themed lures and has used Microsoft Graph API for command and control to blend with legitimate cloud traffic. ClientKing supports remote shell access, SOCKS pivoting, DNS tunneling, and in-memory kernel module loading, and has been used to extend access into Linux servers, routers, and other network infrastructure. Associated tooling and reporting also link the cluster to FinalDraft or SquidDoor variants, VARGEIT, web shells, malicious authentication modules for credential theft, kernel-module rootkits, process injection, and DLL sideloading. A major Jewelbug espionage pattern involves compromising shared webmail or web-hosting infrastructure used by multiple government tenants, then injecting malicious JavaScript as a watering-hole mechanism. In observed campaigns, this enabled theft of browser cookies and email-related data, victim filtering based on targeted government domains, and selective delivery of follow-on malware to Windows users. The scale of collection attributed to the group includes very large volumes of stolen browser cookies, captured credentials, and exfiltrated email content, indicating sustained access to government communications ecosystems. Alongside espionage, Jewelbug has operated large-scale cryptocurrency fraud campaigns targeting Chinese-speaking users. These operations used SEO poisoning, AI-generated lure pages, fake exchange-download portals, and click-fraud infrastructure to drive victims to malicious content. The same browser-focused tooling used in espionage has also supported crypto theft, including functionality consistent with clipboard-based wallet-address replacement. This dual-use infrastructure and overlap between espionage and fraud distinguish Jewelbug from more narrowly missioned state operators. The dominant assessed motivation is espionage, given the sustained targeting of governments, militaries, police, and foreign ministries, although the actor also demonstrably pursues financial gain through cryptocurrency theft and fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
102 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hack-for-hire group conducting parallel cyber espionage against governments and militaries and financially motivated cryptocurrency fraud using shared infrastructure and the XG-Web framework.
Conducts Chinese-linked cyber espionage against government, military, and government communications targets across the Middle East, Southeast Asia, and South Asia, while also running financially motivated cryptocurrency fraud campaigns using shared infrastructure.
Conducting dual-use operations involving international cyber espionage and cryptocurrency theft, using custom malware implants, a custom C2 panel, malicious browser extensions, and large-scale fake cryptocurrency and betting websites.
Conducting dual-use operations combining espionage against government and military targets with large-scale cryptocurrency fraud, including compromising shared government webmail infrastructure, stealing cookies and credentials, deploying backdoors and malicious browser extensions, and operating fake crypto exchange and SEO/click-fraud infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.