Published Security3 min read
One script tag, 15 government webmail tenants: Jewelbug ran spying and crypto fraud off the same panel
Symantec says the China-based group got write access to a shared government webmail installation and hooked the login page and every mailbox view for more than 15 tenants.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Symantec attributes the campaign to a China-based hacker group tracked as Jewelbug, also known as Earth Alux and REF7707.
- Jewelbug has targeted government agencies and organizations in defense, telecommunications, education and aviation, and its cryptocurrency-related activity suggests it may also operate as a hack-for-hire group seeking to profit from cybercrime.
- In a recent operation, Jewelbug compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.
- Symantec researchers found that the espionage campaign and the cryptocurrency fraud were conducted from the same control panel.
- The group gained write access to the shared webmail installation and inserted a malicious script into its common template.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Symantec says the China-based group it tracks as Jewelbug obtained write access to a webmail installation shared by multiple government ministries and agencies, then inserted a single malicious script tag into the common template, so the hook fired on the login page and on every mailbox view across more than 15 government tenants [1][6][7][11]. The researchers also say the espionage campaign and an "industrial-scale cryptocurrency fraud business" were operated from the same control panel [4][14].
The tenancy is the story. According to Symantec, the group reached the webmail platform by compromising a shared web-hosting environment operated by the state telecommunications provider and a national services agency [10]. One edit to one template gave the operators execution on login pages belonging to nine government domains, with the injected JavaScript opening a WebSocket to the command-and-control server on every login [11][6][8]. The script exfiltrated webmail session cookies and read the user's email address to decide whether the account sat on a targeted government domain [8].
Accounts that passed that filter got a fake Adobe Flash update prompt, which installed the Antino backdoor on Windows along with browser tooling [9]. Symantec says Antino is delivered through malicious HTA files and fake Adobe installers and is then used to stage further payloads [15], one of which is a Chrome and Firefox extension called PDF Viewer that steals cookies and credentials, intercepts traffic, injects JavaScript and exposes browser functions remotely [16]. The group also runs a framework called XG-Web for managing campaigns and victim data [17].
Symantec traced Antino infections back to Jewelbug's infrastructure and then obtained visibility into the C2 management platform, its database, server logs, source code and operator files [18]. That database holds more than a million implant check-in rows, more than 580,000 stolen browser cookies, several thousand captured credentials and more than 2,300 exfiltrated email bodies [19]. The collection profile is heavily weighted toward session material: roughly 250 stolen cookies for every exfiltrated message body [26]. Runtime logs recorded about 1.1 million geolocation events against roughly 4,300 distinct source IP addresses, including about 87,200 connections from a Southeast Asian country against state telecom and military networks, about 53,100 from a Middle Eastern country across the national carrier's ranges including Starlink-connected addresses in the capital, and about 15,000 from a second Southeast Asian country including government ministry infrastructure [20]. Those three named clusters account for roughly 14 percent of the recorded events [27].
The fraud side of the same panel is industrialised in a way that mirrors the espionage side. Symantec describes an automated pipeline that scrapes keywords, generates thousands of fake download pages with AI and publishes them across a 44-server content-management fleet and hundreds of lookalike domains impersonating OKX and Binance, with click bots pushing search rankings [22][21]. Other lures include sports betting, pirated livestream portals and private detective scams [23]. Symantec attributes the financially motivated activity to a Chinese company with high confidence [24], and notes the crypto work suggests Jewelbug may also operate as a hack-for-hire outfit [2].
Worth watching: whether any government operator of shared webmail publishes an account of how template write access was obtained and how long the hook ran; whether other vendors corroborate the single-panel finding rather than treating the espionage and fraud as separate actors; and whether the Chinese company Symantec identifies draws any regulatory or sanctions response. Anyone running multi-tenant webmail should treat template write access as a compromise of every tenant at once, and expect the first loss to be session cookies rather than passwords [7][8].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Symantec attributes the campaign to a China-based hacker group tracked as Jewelbug, also known as Earth Alux and REF7707.
- [2]
Jewelbug has targeted government agencies and organizations in defense, telecommunications, education and aviation, and its cryptocurrency-related activity suggests it may also operate as a hack-for-hire group seeking to profit from cybercrime.
- [3]
In a recent operation, Jewelbug compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.
- [4]
Symantec researchers found that the espionage campaign and the cryptocurrency fraud were conducted from the same control panel.
- [6]
The group gained write access to the shared webmail installation and inserted a malicious script into its common template.
- [7]
The injected script ran on login pages and mailbox views across 15 tenants; Symantec states that a single campaign spanned more than 15 government webmail tenants, with the hook firing on the login page and every mailbox view.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comBill ToulasAug 13Hackers breach govt webmail while running parallel crypto fraud
Additional citations
- Symantec, via BleepingComputer
- BleepingComputer
- Symantec



