Jewelbug—also tracked as Earth Alux, REF7707, and CL-STA-0049—has been identified as a China-based hackers-for-hire group running state-aligned espionage campaigns alongside a large-scale cryptocurrency fraud operation from the same infrastructure. Researchers said the group targeted government ministries, militaries, police, and government email accounts across the Middle East, Southeast Asia, and South Asia, including a campaign that compromised a shared government webmail platform and turned it into a watering hole affecting more than 15 government tenants.
The operation relied on the browser-focused XG-Web remote-access and information-stealing platform, the Antino Windows backdoor, a malicious "PDF Viewer" browser extension, and the ClientKing Linux/router implant. Investigators reported that the victim database logged more than 1 million implant check-ins, over 580,000 stolen browser cookies, thousands of credentials, and thousands of exfiltrated email bodies in under three months. The same operators also ran SEO-poisoning and fake exchange-download campaigns impersonating OKX and Binance to target Chinese-speaking cryptocurrency users, and the commercial side of the activity was linked to a registered company in Hunan, China, suggesting the fraud operation may have supplied access, delivery, or support for the espionage campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On August 13, Broadcom’s Threat Hunter Team reported that Jewelbug’s shared espionage and crypto-fraud operations were run by the same small team, identifying an operator as “ople500” and linking that activity to the “paopaodada” persona. Broadcom further assessed with high confidence that a Changsha, Hunan SEO business and its legal representative supplied access, infrastructure, and delivery for the espionage operation.
In October 2025, Jewelbug was attributed to a five-month intrusion targeting a Russian IT service provider. The intrusion reportedly deployed malware capable of interfering with the normal functioning of security tools.
Check Point Research reported a sustained Ink Dragon espionage campaign, overlapping with Jewelbug and CL-STA-0049, that showed increased targeting of European government entities while continuing operations in Southeast Asia and South America. The report also described the actor’s use of compromised IIS servers as a ShadowPad-based relay network and noted mass scanning for the SharePoint ToolShell exploit chain during early exploitation waves in July 2025.
Palo Alto Networks Unit 42 reported that suspected China-linked cluster CL-STA-0049 had been active since at least March 2023, targeting government, defense, telecommunications, education, and aviation organizations in Southeast Asia and South America. The report detailed the Squidoor (FinalDraft) backdoor, IIS exploitation, ASPX web shells, and covert C2 methods including Outlook API, DNS tunneling, and ICMP tunneling.
Symantec reporting said Jewelbug also breached a major U.S. industrial manufacturer, expanding the known victimology beyond government, military, and telecom targets in Asia and the Middle East. The disclosure indicates the group's operations affected at least one significant U.S. private-sector victim as well.
In the group's largest espionage campaign, Jewelbug compromised a shared web-hosting and government webmail platform operated by a state telecommunications provider and national network-services agency in a Middle Eastern country. This let the attackers deploy one watering-hole script across more than 15 government webmail tenants simultaneously.
The sources state that Jewelbug operated both state-aligned espionage campaigns and a for-profit cryptocurrency fraud operation from the same control panel and backend infrastructure. The overlap linked government intrusions with fake exchange-download schemes targeting Chinese-speaking cryptocurrency users.
Reporting describes Jewelbug, a China-based hackers-for-hire group, conducting espionage intrusions against government ministries and related government targets across the Middle East, Southeast Asia, South Asia, and Asia more broadly. The activity included targeting militaries, police, and government email accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceinfosecurity-magazine.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcesecurity.com
Open sourceresearch.checkpoint.com
Open sourcetrendmicro.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.