PDF Viewer is a malicious browser extension used by the China-linked threat actor Jewelbug, also tracked as Earth Alux and REF7707, in both cyber-espionage and cryptocurrency theft operations. Despite its benign-sounding name, it functions as browser-based surveillance and theft tooling rather than a document viewer. It has been observed targeting Chrome and Firefox users and is deployed alongside other Jewelbug malware, including the Antino Windows backdoor, as part of broader intrusion and fraud campaigns.
The extension is designed to obtain extensive browser access and collect high-value user data. Reported capabilities include theft of browser cookies, session tokens, credentials, browsing history, screenshots, and traffic data. It can intercept browser activity, inject arbitrary JavaScript into webpages, and remotely expose browser functions to operators, enabling interaction with the victim browser in a manner similar to the legitimate user. This makes it useful for account takeover, surveillance of authenticated sessions, and follow-on abuse of web applications.
PDF Viewer has also been associated with cryptocurrency theft activity. It can manipulate browser sessions to alter transaction details, including silently replacing cryptocurrency destination addresses during transfers. This aligns it with Jewelbug’s financially motivated operations, which have included large-scale fake cryptocurrency and betting infrastructure, while also supporting espionage objectives through theft of authenticated web data and credentials.
Observed delivery has included installation as an additional payload after compromise by Antino, including campaigns in which victims were shown fake Adobe Flash update prompts on compromised webmail infrastructure. Jewelbug has used these operations against government, military, telecommunications, and industrial targets across the Middle East and Asia, with the extension serving as a flexible post-compromise collection and browser-manipulation component.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This extension is particularly versatile, capable of stealing cookies, session tokens, and screenshots, injecting JavaScript, and potentially replacing cryptocurrency addresses during transactions.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The script enlisted them in the XG-Web panel, stole their login cookies... researchers found more than 580,000 full browser cookie jars... and several thousand login credentials in Jewelbug's coffers
"the malicious code activating on the login page and every mailbox view to exfiltrate cookies over a WebSocket connection and serve a next-stage payload" | "a web hosting provider was compromised to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government. The watering hole campaign spanned 15 government webmail tenants"
"...which ran operator commands through the Windows command interpreter and returned the output to the panel"
The script enlisted them in the XG-Web panel, stole their login cookies... researchers found more than 580,000 full browser cookie jars... and several thousand login credentials in Jewelbug's coffers
Symantec researchers discovered hundreds of thousands of stolen cookies and thousands of login credentials...
"The extension grants the ability to... harvest credentials by hooking login forms, cookies, browsing history, bookmarks, screenshots, clipboard, and web traffic."
One of the payloads is a malicious browser extension for Chrome and Firefox, named PDF Viewer, which steals cookies and credentials
"The extension grants the ability to... harvest credentials by hooking login forms, cookies..." and "the malicious code activating on the login page and every mailbox view to exfiltrate cookies over a WebSocket connection"
Symantec researchers discovered hundreds of thousands of stolen cookies and thousands of login credentials...
"The extension grants the ability to... harvest credentials by hooking login forms, cookies, browsing history, bookmarks, screenshots, clipboard, and web traffic."
One of the payloads is a malicious browser extension for Chrome and Firefox, named PDF Viewer, which steals cookies and credentials
This extension is particularly versatile, capable of stealing cookies, session tokens, and screenshots...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious browser extension used by Jewelbug to steal cookies, session tokens, screenshots, inject JavaScript, and potentially swap cryptocurrency addresses during transactions.
A malicious Chrome and Firefox browser extension used as a payload to steal cookies and credentials, intercept traffic, inject JavaScript, and expose browser functions remotely.
A malicious browser extension used by Jewelbug to steal cookies, session tokens, browsing history, screenshots, traffic, and other browser data. It can inject arbitrary JavaScript, interact with the browser as the victim, escape the browser sandbox, and includes functionality to replace cryptocurrency wallet addresses during transactions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.