Executive Summary
On August 13, 2026, Broadcom’s Threat Hunter Team — pooling analysts from Symantec and Carbon Black — published findings on a China-based threat actor it tracks as Jewelbug, a name that unifies what several other vendors have been separately calling Earth Alux (Trend Micro), Ink Dragon (Check Point), REF7707 (Elastic Security Labs), and CL-STA-0049 (Palo Alto Networks Unit 42). The report’s central finding is unusual even by APT standards: the same small team, working from a single control panel called XG-Web, runs both a nation-state-aligned espionage program against governments and militaries across the Middle East, Southeast Asia, and South Asia, and a for-profit cryptocurrency fraud operation targeting Chinese-speaking crypto users worldwide.
In its most significant disclosed operation, Jewelbug compromised a shared webmail hosting provider and used that single point of access to inject malicious JavaScript into the webmail platforms of at least 15 government ministries in one Middle Eastern country simultaneously — turning ordinary staff logins into a mass credential- and cookie-harvesting operation. In parallel, the group operated an industrialized crypto-fraud pipeline that used AI-generated fake exchange pages to impersonate Binance and OKX, spreading across more than 40 content-management servers and hundreds of lookalike domains. Across the observed window, Jewelbug’s infrastructure logged over one million implant check-ins, more than 580,000 stolen browser cookies, several thousand harvested credentials, and roughly 2,300 exfiltrated email bodies — in under three months of monitored activity alone. Researchers have gone further than usual on attribution, tying at least one operator’s handle (“paopaodada,” or “bubble boss”) to a real, registered SEO company based in Changsha, Hunan Province.
Jewelbug is not a brand-new entity — its Earth Alux/REF7707 lineage has been tracked in espionage campaigns since at least 2025 — but the August 2026 disclosure is the first to unify its identity across vendor silos and to expose the dual espionage/crime business model, making it a newly significant, high-confidence threat actor warranting its own profile.
Threat Actor Profile
Suspected origin: China, operating from infrastructure and work patterns consistent with the UTC+8 timezone (activity peaks in local afternoons and late evenings).
Motivation: Dual — state-aligned intelligence collection (government, military, and telecom espionage) combined with independent, profit-driven cybercrime (cryptocurrency fraud). Researchers assess Jewelbug as a hackers-for-hire operation rather than a directly tasked intelligence unit, meaning it likely serves state or quasi-state clients on a contract basis while also running its own criminal side business using the same tooling and infrastructure.
Suspected affiliation: Broadcom researchers stopped short of formal government attribution but characterized Jewelbug as operating a business model increasingly common among Chinese contractor APT groups — private companies or front businesses that perform espionage work for state clients while monetizing their access and tooling independently. The identification of a legally registered Changsha SEO company tied to a panel operator’s handle supports this “front business” model rather than a purely military or intelligence-service structure.
Known aliases: Jewelbug (Broadcom/Symantec), Earth Alux (Trend Micro), Ink Dragon (Check Point), REF7707 (Elastic Security Labs), CL-STA-0049 (Palo Alto Networks Unit 42).
Team structure: Researchers found panel accounts under usernames “admin” and “admin_s,” the latter using the display nickname “ople500.” The panel operator advertising services as “paopaodada” is the identified legal representative of the Changsha-based SEO business, suggesting a small, tightly held operating team rather than a large, compartmentalized organization.
TTPs and Tradecraft
Jewelbug’s tradecraft spans initial access, a custom malware suite, and a purpose-built command-and-control platform that supports both its espionage and fraud lines of business.
Initial access. Historical Earth Alux/REF7707 activity documented by Trend Micro shows the group favoring exploitation of internet-facing infrastructure — vulnerable IIS servers and SharePoint instances — to plant webshells as an initial foothold, followed by staged backdoor deployment. In the August 2026 campaign, Jewelbug’s signature technique was a watering-hole compromise of a shared web hosting provider, allowing the group to inject malicious JavaScript across the webmail installations of multiple government tenants that happened to share hosting infrastructure — a single supply-chain-style compromise cascading into simultaneous access at 15+ government ministries.
Command-and-control: XG-Web. The group’s unifying infrastructure is a browser-centric remote-access and information-stealing platform built on a React front-end, Node.js backend, and MySQL database. XG-Web is used to administer both the espionage implants and the crypto-fraud campaigns from one interface. To evade detection, the platform submits its own payloads to VirusTotal every 12 hours to monitor for detection signature changes and rotate infrastructure accordingly. Payloads have been observed hosted on public Google Docs links, XOR-encoded to evade content scanning, and served from typosquatted domains mimicking legitimate services such as Google Fonts and Microsoft resources.
Browser implant — “PDF Viewer” extension. A malicious Chrome/Firefox extension masquerading as a document viewer requests an unusually broad permission set: cookies, debugger access, native messaging, script injection, web request interception, and download monitoring. It escapes the browser sandbox via a native-messaging host component named com.microsoft.runedge — a deliberately Microsoft-styled name designed to blend into legitimate system processes. The extension harvests saved credentials, cookies, browsing history, bookmarks, screenshots, and clipboard content. Notably, researchers found the extension includes a cryptocurrency clipboard-swapping (“clipper”) function — capable of silently replacing a copied wallet address with an attacker-controlled one — that was present in the code but not observed active during the monitored campaign window.
Windows backdoor — Antino. Delivered via malicious HTA downloaders and fake Adobe installer prompts, Antino uses the Microsoft Graph API as its command-and-control channel, blending its traffic into legitimate Microsoft 365 API calls. Antino is used to sideload the PDF Viewer extension and its native-messaging helper onto compromised Windows endpoints.
Linux/router implant — ClientKing. A Rust-based implant observed in at least 37 distinct builds, ClientKing targets Linux servers and network edge devices, including ASUS consumer routers, across both x86-64 and ARM64 architectures. It supports five separate C2 channels including DNS tunneling and SOCKS proxy pivoting, and can load kernel modules directly from memory. A companion technique hooks the su and sudo authentication binaries on compromised Linux hosts to harvest credentials at the point of privilege escalation.
Historical toolkit. Under its Earth Alux/REF7707 identity, Trend Micro has previously documented the group’s use of first-stage backdoors COBEACON and VARGEIT, with VARGEIT serving flexibly as a first-, second-, or later-stage implant. The malware family tracked as VARGEIT by Trend Micro overlaps with what other vendors call SQUIDOOR, and REF7707 activity has separately used a backdoor dubbed FinalDraft — illustrating the same cross-vendor naming fragmentation that the Jewelbug designation is now attempting to resolve.
Cryptocurrency fraud tradecraft. On the criminal side, Jewelbug operates what amounts to an industrialized SEO-poisoning and phishing pipeline: an automated system scrapes trending cryptocurrency keywords, uses AI generation to build thousands of fake exchange-download pages impersonating Binance and OKX, and publishes them across a fleet of more than 40 content-management servers and hundreds of lookalike domains, supplemented by click-fraud bots to inflate search visibility. The operation is publicly marketed on Telegram as a legitimate “search-ranking rental” SEO service — a thin front for the phishing infrastructure underneath.
Targeting and Victim Sectors
Jewelbug’s espionage arm has concentrated on:
- Government and military entities in the Middle East, Southeast Asia, and South Asia, including a single operation compromising 15+ government webmail tenants in one Middle Eastern country and targeting of 90+ police and government email addresses across South Asia.
- Telecommunications and national carrier infrastructure, with observed connection volumes in the tens of thousands across Middle Eastern (roughly 53,100 connections) and Southeast Asian (roughly 87,200 connections) telecom and military networks, plus government ministry infrastructure (roughly 15,000 connections).
- Aerospace and industrial manufacturing — Symantec identified compromise of an internal proxy belonging to a major U.S. aerospace and industrial manufacturer, indicating targeting extends beyond the group’s core Asia/Middle East geography.
- Russia — a five-month intrusion into a Russian IT service provider was attributed to the group starting around October 2025, notable given China and Russia’s generally cooperative diplomatic posture, and consistent with historical precedent of Chinese APT groups conducting opportunistic intelligence collection against Russian targets.
- Taiwan — decoy documents impersonating Taiwanese government entities suggest an additional targeting vector consistent with China’s long-standing intelligence priorities regarding Taiwan.
On the fraud side, victims are Chinese-speaking cryptocurrency users globally, lured through fake exchange-download pages and SEO-poisoned search results rather than direct targeting of any single organization.
Earth Alux’s broader historical footprint, as documented by Trend Micro prior to the Jewelbug unification, additionally covers government, technology, logistics, manufacturing, telecommunications, IT services, and retail organizations across the Asia-Pacific region and Latin America — indicating the group’s operational reach is considerably wider than the Middle East-focused campaign that drove the August 2026 disclosure.
Historical Incidents and Impact
Jewelbug’s constituent identities have been tracked independently for well over a year before researchers connected the dots:
- Pre-2026 (as Earth Alux/REF7707): Trend Micro and Elastic Security Labs separately documented espionage campaigns using COBEACON, VARGEIT/SQUIDOOR, and FinalDraft backdoors against government, technology, telecom, logistics, manufacturing, IT services, and retail targets across APAC and Latin America, entering environments via webshells planted on vulnerable IIS and SharePoint servers.
- October 2025: A five-month-long intrusion into a Russian IT service provider, later attributed to the group by Broadcom researchers.
- Through mid-2026: Development and expansion of the crypto-fraud side business — the AI-generated fake exchange page network, the 40+ server content-management fleet, and the Telegram-marketed “SEO service” front — running in parallel with, and administered from the same panel as, the espionage operations.
- August 13, 2026: Broadcom’s Threat Hunter Team publishes the unifying “Jewelbug” report, disclosing the 15-tenant government webmail watering-hole compromise, the XG-Web panel architecture, the PDF Viewer browser extension, the Antino and ClientKing malware families, and attribution details tying an operator to a Hunan-registered business — consolidating years of fragmented, multi-vendor tracking into a single actionable profile.
The cumulative scale disclosed — over one million implant check-ins, 580,000+ stolen cookies, thousands of credentials, and roughly 2,300 exfiltrated email bodies within less than three months of the monitored window alone — indicates an operation of considerable maturity and volume, not an opportunistic or low-effort actor. The 15-tenant simultaneous government compromise, achieved through a single shared-hosting-provider breach, is a particularly notable proof of concept for how one supply-chain foothold can cascade into mass government access.
Defensive Implications
Jewelbug’s tradecraft points to several concrete defensive priorities for potentially targeted organizations, especially governments, telecoms, and manufacturers in its focus regions:
- Audit shared hosting and webmail infrastructure. The group’s most damaging technique was compromising a single shared hosting provider to reach many downstream government tenants at once. Organizations relying on shared or outsourced webmail/hosting infrastructure should demand evidence of tenant isolation and monitor for unauthorized JavaScript injection on login and mailbox pages.
- Treat unsolicited browser extensions as a primary threat vector. The “PDF Viewer” extension’s broad permission requests (cookie access, native messaging, script injection) are a textbook red flag. Enterprises should restrict extension installation to vetted allowlists and monitor for native-messaging hosts with suspicious naming patterns mimicking legitimate vendors.
- Monitor Microsoft Graph API traffic for anomalies. Antino’s use of Graph API as a C2 channel exploits the difficulty of distinguishing malicious API calls from legitimate Microsoft 365 usage; anomaly detection on Graph API call patterns and volumes is warranted for Microsoft 365 tenants in targeted sectors.
- Harden Linux/router edge devices. ClientKing’s targeting of consumer-grade routers and its
su/sudocredential-hooking technique underscore that edge and IoT-adjacent infrastructure remains a soft target; firmware patching and monitoring of authentication binary integrity are worthwhile controls. - Educate users against fake exchange and update pages. The crypto-fraud side of the operation succeeds through AI-generated, highly convincing fake exchange pages — a reminder that user-facing brand-impersonation detection and takedown capacity remains a necessary complement to endpoint controls.
- Expect continued naming fragmentation but converging identity. Security teams should map Jewelbug/Earth Alux/Ink Dragon/REF7707/CL-STA-0049 to a single tracking entry in threat intelligence platforms to avoid under-prioritizing an actor that appears, under each individual alias, as a smaller and less active group than it actually is.
Jewelbug’s dual-use model — one team, one panel, two revenue streams, serving both state interests and personal profit — reflects a broader and increasingly documented trend among Chinese contractor APT groups, and organizations across government, telecom, and manufacturing sectors in its target regions should treat both faces of the group as expressions of the same operational risk.