Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
One of the payloads is a malicious browser extension for Chrome and Firefox, named PDF Viewer, which steals cookies and credentials, intercepts traffic, injects JavaScript, and remotely exposes browser functions.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The script enlisted them in the XG-Web panel, stole their login cookies... researchers found more than 580,000 full browser cookie jars... and several thousand login credentials in Jewelbug's coffers
The extension talked to a Windows helper registered as a native-messaging host under the misleading name com.microsoft.runedge, which ran operator commands through the Windows command interpreter and returned the output to the panel.
The extension harvested credentials by hooking login forms... The group also hooked the hosting provider's own administrators to harvest the credentials that granted that write access.
The extension harvested credentials by hooking login forms... The group also hooked the hosting provider's own administrators to harvest the credentials that granted that write access.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious Chrome and Firefox browser extension used as a payload to steal cookies and credentials, intercept traffic, inject JavaScript, and expose browser functions remotely.
A malicious browser extension used by Jewelbug to steal cookies, session tokens, browsing history, screenshots, traffic, and other browser data. It can inject arbitrary JavaScript, interact with the browser as the victim, escape the browser sandbox, and includes functionality to replace cryptocurrency wallet addresses during transactions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.