Chinese state-linked hackers, identified as the Jewelbug group, infiltrated a major Russian IT service provider in a sophisticated espionage campaign that spanned from January to May 2025. The breach was uncovered by Symantec researchers, who reported that the attackers gained access to the company’s software build and code repository systems, raising concerns about a potential software supply chain attack targeting the provider’s downstream clients. The targeted company, though unnamed, is described as a significant provider with government-related clients, amplifying the potential impact of the intrusion. Jewelbug, also tracked as Earth Alux, CL-STA-0049, and REF7707 by various security vendors, has a history of targeting government and corporate networks across South America, South and Southeast Asia, and Taiwan, but this marks a rare incursion into Russian infrastructure. The attackers conducted extensive reconnaissance, stole credentials, and maintained persistent access within the network, demonstrating advanced operational capabilities. Notably, the group used Yandex Cloud, a legitimate Russian cloud platform, to exfiltrate data, a tactic likely chosen to evade detection by blending malicious activity with normal network traffic. The use of Yandex Cloud is particularly effective in Russia, as it is a trusted domestic service and unlikely to be blocked or scrutinized by local enterprises. Technical analysis revealed that the attackers leveraged a renamed version of Microsoft Console Debugger (cdb.exe) to run shellcode, bypass application allowlisting, and disable security solutions, further highlighting the sophistication of the operation. The campaign is assessed to be part of a broader espionage effort, with no evidence of financial motivation. Researchers also observed the deployment of advanced malware, including FINALDRAFT (aka Squidoor), capable of infecting both Windows and Linux systems, and noted the possible development of new backdoors during related intrusions. The breach underscores that Russia is not immune to Chinese cyber espionage, despite close diplomatic and economic ties between the two countries. The incident has raised concerns about the security of Russian government and corporate networks, particularly those relying on IT service providers for software distribution and network management. The potential for a supply chain attack means that dozens of Russian companies could have been exposed to further compromise. The Jewelbug group’s operations reflect a growing trend of state-sponsored actors targeting IT service providers to maximize access and impact. The incident also highlights the importance of monitoring legitimate cloud services for signs of abuse in cyber operations. Security experts recommend heightened vigilance and improved monitoring of software build environments and cloud service usage to detect and mitigate similar threats. The breach serves as a reminder that geopolitical alliances do not guarantee immunity from cyber espionage activities. Ongoing analysis is expected to reveal further details about the attackers’ methods and the full scope of the compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On publication of the research, Symantec's Threat Hunter Team linked the five-month compromise of the Russian IT services provider to the China-linked group Jewelbug, also tracked as CL-STA-0049, Earth Alux, and REF7707. The disclosure also highlighted related Jewelbug activity against targets in South America, South Asia, and Taiwan, including use of a Microsoft Graph API and OneDrive-based backdoor.
During analysis of the intrusion, Symantec determined the attackers' access to code repositories and software build systems could have enabled a software supply-chain attack affecting the provider's Russian customers. The finding marked a rare publicly reported case of suspected Chinese cyber-espionage targeting Russian infrastructure.
Over roughly five months in 2025, the attackers used stealthy tradecraft such as renamed Microsoft debugging tools, credential dumping, scheduled-task persistence, and event log clearing while operating inside the Russian provider's network. They also used cloud services including Yandex Cloud for exfiltration or command-and-control to blend with normal traffic.
A China-linked threat actor later identified as Jewelbug began a covert intrusion against a Russian IT services provider in early 2025. The attackers established access to internal systems including code repositories, build servers, and other sensitive infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcesecurityonline.info
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcetherecord.media
Open sourcethehackernews.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.