Skip to content

Security1 publisher3 min readPublished

One console, two businesses: Broadcom says Jewelbug runs espionage and crypto fraud together

Broadcom's Threat Hunter Team says the same small team, the same infrastructure and one control panel serve both Chinese state espionage and a crypto-fraud sideline. Actor-type triage does not survive that.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Broadcom's Threat Hunter Team published a report on Jewelbug on August 13.
  • The Broadcom threat intelligence team brought together experts from Symantec and Carbon Black.
  • Broadcom researchers revealed that Jewelbug, a threat group associated with Chinese-sponsored cyber espionage operations, may be a hacker-for-hire group that also runs profitable crypto fraud campaigns.
  • Jewelbug is also known as Ink Dragon, Earth Alux, REF770 and CL-STA-0049.
  • Jewelbug uses the same infrastructure to conduct espionage against governments and militaries across the Middle East, Southeast Asia and South Asia and to run a financially motivated operation targeting Chinese-speaking cryptocurrency users through fake exchange-download portals.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Broadcom's Threat Hunter Team, which pools Symantec and Carbon Black researchers, published a report on August 13 arguing that Jewelbug, a group several vendors track as a Chinese state espionage actor, runs a cryptocurrency fraud business from the same infrastructure it uses against governments and militaries [1][2][3][5]. The claim is administrative rather than technical, and that is what makes it awkward: "The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel," the researchers wrote [6]. Plenty of internal escalation policy is keyed to the actor label before anyone has finished looking at the artefacts. A fake exchange-download portal aimed at Chinese-speaking crypto users gets routed to fraud [5]. A web shell on an internet-facing SharePoint box gets routed to the espionage queue [9]. According to Broadcom, at Jewelbug both roads lead to XG-Web, a browser-based command-and-control platform that acted as the central management console for both campaigns, with implants, stolen data and operator activity feeding a shared backend database [7]. If the same console administers both sets of victims, then the low-status intrusion in your environment is a live indicator for the high-status one. The espionage side is not novel in tradecraft and has been reported before by Trend Micro's TrendAI, Palo Alto Networks' Unit 42 and Check Point Research [21]. Access typically came through vulnerable IIS and SharePoint servers, followed by web shells and a backdoor tracked variously as VARGEIT, Squidoor and FinalDraft [9], with covert channels over Microsoft Graph and Outlook APIs, DNS tunnelling and ICMP tunnelling [10]. A Windows backdoor Broadcom calls Antino also talked to operators over the Microsoft Graph API so its traffic blended with legitimate Microsoft cloud services, and was delivered through fake software installers and themed lures [8]. The scale numbers are the part worth taking to a risk conversation. Broadcom says it found a victim database recording more than one million implant check-ins and over 580,000 stolen browser cookies in less than three months of active operations [12], which works out to an average above 11,000 check-ins [22] and roughly 6,400 cookies a day [23]. Targets included several government organisations in the Middle East and Southeast Asia plus more than 90 police and government email addresses in South Asia [11]. One set of implants was configured to use the internal proxy of a major US aerospace and industrial manufacturer [13]. In the largest operation, a single planted script placed a watering hole on more than 15 government webmail tenants in one Middle Eastern country at once [14]. Decoy documents themed on Taiwanese government bodies suggested an interest in Taiwan [15]. The through line, per Broadcom, is government communications systems and the service providers that host them, which yields durable access to official correspondence [16]. The attribution work is where the two halves meet in person. Broadcom names an operator that appears in the control panel as 'ople500', likely running what it calls the commercial arm, and links that account to a 'paopaodada' persona [17] advertised on Telegram as the contact for a "website ranking rental" service [18]. It associates that individual with high confidence to an SEO company registered in Changsha, capital of Hunan province [19], and says the firm's sole legal representative supplies access, infrastructure and delivery to the espionage operation rather than sitting among the operators [20]. That is a supply relationship, not a chain of command. Watch whether other vendors corroborate the shared-console finding, since this rests on one team's months-long investigation and Broadcom's own hedge that Jewelbug may be a hacker-for-hire outfit rather than a purely state-run one [3].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories