Published Invest3 min read
One command-and-control stack, two crime scenes: Symantec puts espionage and wallet draining on the same rails
Symantec's Threat Hunter Team says the group it calls Jewelbug ran government spying and fake crypto exchanges from a single platform.
Context for builders, not their beat.See today for builders

What happened
- Symantec's Threat Hunter Team published findings that a China-based hacker-for-hire group called Jewelbug has been running government espionage campaigns and cryptocurrency fraud operations simultaneously, using the same infrastructure for both.
- Jewelbug's centralised command-and-control platform, called XG-Web, serves as the operational nerve centre and can simultaneously manage espionage implants on government systems and coordinate fake crypto exchange campaigns.
- XG-Web has tracked over one million implant check-ins across its victim database.
- The group has stolen more than 580,000 browser cookies.
- The group has exfiltrated over 2,300 email bodies.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Symantec's Threat Hunter Team says a China-based hacker-for-hire group it tracks as Jewelbug has been running government espionage campaigns and cryptocurrency fraud at the same time, on the same infrastructure [1]. That erases a boundary most security budgets are drawn around, in which nation-state intrusion belongs to enterprise incident response and wallet drainers belong to exchange trust and safety.
The connective tissue, according to Symantec, is a centralised command-and-control platform called XG-Web, which can manage espionage implants on government systems and coordinate fake crypto exchange campaigns from the same console [2]. Symantec says XG-Web's victim database has logged more than one million implant check-ins [3], along with more than 580,000 stolen browser cookies and over 2,300 exfiltrated email bodies [4][5]. The publisher's own summary renders that as "over a million victims" [6], which is not the same unit: check-ins accumulate per implant over time, so the figure describes telemetry volume rather than headcount [1]. Operators reading vendor research should hold that distinction, because the ratio inside the numbers is the more useful signal. Roughly 252 cookies were taken for every email body pulled [2], which is the profile of bulk session harvesting rather than patient diplomatic reading.
Symantec dates the group, also called Earth Alux and REF7707, to mid-2023 [7], with espionage aimed primarily at government entities in the Middle East, Southeast Asia, South Asia and Taiwan [8]. One campaign put a malicious script across more than 15 government webmail tenants sharing a hosting platform, a waterhole approach [9]. On the fraud side, Symantec reports hundreds of lookalike domains and thousands of fake downloads for crypto exchanges, generated with AI and aimed mainly at Chinese-speaking victims [10][11]. The tooling includes a custom Windows backdoor called Antino and a browser extension whose clipboard module silently swaps a copied wallet address for one the group controls [12][13]. Distribution leans on SEO poisoning to push malicious sites up the results for popular platforms [14].
The consequence is procedural, not dramatic. Domain takedown feeds, lookalike-brand monitoring and drainer address blocklists are typically owned by consumer-facing abuse teams and treated as commodity fraud work. If the registration and hosting sit behind the same controller as implants on government webmail, that abuse telemetry becomes counterintelligence-grade indicator material, and the IR team investigating a webmail compromise may find its best pivot in an exchange's phishing domain list. Neither side currently reads the other's tickets.
Two caveats. This is one vendor's account, relayed through one publication, and the shared-infrastructure claim is the load-bearing part; earlier reporting dating to October 2025 had already covered Jewelbug's geopolitical targeting, with the crypto fraud dimension described as the new element [15]. Symantec also characterises the operation as a relatively small team using role-based access controls [16], which is the detail that makes the dual mandate plausible rather than a coincidence of reused hosting.
What to watch: whether a second vendor corroborates that espionage implants and fraud domains answer to one controller; whether exchanges start publishing drainer indicators in formats enterprise IR can ingest; and whether the million-check-in number gets restated as something closer to a victim count.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Symantec's Threat Hunter Team published findings that a China-based hacker-for-hire group called Jewelbug has been running government espionage campaigns and cryptocurrency fraud operations simultaneously, using the same infrastructure for both.
- [2]
Jewelbug's centralised command-and-control platform, called XG-Web, serves as the operational nerve centre and can simultaneously manage espionage implants on government systems and coordinate fake crypto exchange campaigns.
- [3]
XG-Web has tracked over one million implant check-ins across its victim database.
- [4]
The group has stolen more than 580,000 browser cookies.
- [5]
The group has exfiltrated over 2,300 email bodies.
- [6]
CryptoBriefing's subheadline describes the group as "targeting over a million victims across multiple continents".
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cryptobriefing.comEditorial TeamAug 13Jewelbug runs espionage and cryptocurrency fraud operations, says Symantec
Additional citations
- Symantec Threat Hunter Team, reported by CryptoBriefing
- CryptoBriefing


