Security1 distinct publisher3 min readUpdated
Broadcom's Threat Hunter Team says the same small team, the same infrastructure and one control panel serve both Chinese state espionage and a crypto-fraud sideline. Actor-type triage does not survive that.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Broadcom's Threat Hunter Team says the same small team, the same infrastructure and one control panel serve both Chinese state espionage and a crypto-fraud sideline. Actor-type triage does not survive that.
Broadcom's Threat Hunter Team, which pools Symantec and Carbon Black researchers, published a report on August 13 arguing that Jewelbug, a group several vendors track as a Chinese state espionage actor, runs a cryptocurrency fraud business from the same infrastructure it uses against governments and militaries [1][2][3][5]. The claim is administrative rather than technical, and that is what makes it awkward: "The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel," the researchers wrote [6]. Plenty of internal escalation policy is keyed to the actor label before anyone has finished looking at the artefacts. A fake exchange-download portal aimed at Chinese-speaking crypto users gets routed to fraud [5]. A web shell on an internet-facing SharePoint box gets routed to the espionage queue [9]. According to Broadcom, at Jewelbug both roads lead to XG-Web, a browser-based command-and-control platform that acted as the central management console for both campaigns, with implants, stolen data and operator activity feeding a shared backend database [7]. If the same console administers both sets of victims, then the low-status intrusion in your environment is a live indicator for the high-status one. The espionage side is not novel in tradecraft and has been reported before by Trend Micro's TrendAI, Palo Alto Networks' Unit 42 and Check Point Research [21]. Access typically came through vulnerable IIS and SharePoint servers, followed by web shells and a backdoor tracked variously as VARGEIT, Squidoor and FinalDraft [9], with covert channels over Microsoft Graph and Outlook APIs, DNS tunnelling and ICMP tunnelling [10]. A Windows backdoor Broadcom calls Antino also talked to operators over the Microsoft Graph API so its traffic blended with legitimate Microsoft cloud services, and was delivered through fake software installers and themed lures [8]. The scale numbers are the part worth taking to a risk conversation. Broadcom says it found a victim database recording more than one million implant check-ins and over 580,000 stolen browser cookies in less than three months of active operations [12], which works out to an average above 11,000 check-ins [22] and roughly 6,400 cookies a day [23]. Targets included several government organisations in the Middle East and Southeast Asia plus more than 90 police and government email addresses in South Asia [11]. One set of implants was configured to use the internal proxy of a major US aerospace and industrial manufacturer [13]. In the largest operation, a single planted script placed a watering hole on more than 15 government webmail tenants in one Middle Eastern country at once [14]. Decoy documents themed on Taiwanese government bodies suggested an interest in Taiwan [15]. The through line, per Broadcom, is government communications systems and the service providers that host them, which yields durable access to official correspondence [16]. The attribution work is where the two halves meet in person. Broadcom names an operator that appears in the control panel as 'ople500', likely running what it calls the commercial arm, and links that account to a 'paopaodada' persona [17] advertised on Telegram as the contact for a "website ranking rental" service [18]. It associates that individual with high confidence to an SEO company registered in Changsha, capital of Hunan province [19], and says the firm's sole legal representative supplies access, infrastructure and delivery to the espionage operation rather than sitting among the operators [20]. That is a supply relationship, not a chain of command. Watch whether other vendors corroborate the shared-console finding, since this rests on one team's months-long investigation and Broadcom's own hedge that Jewelbug may be a hacker-for-hire outfit rather than a purely state-run one [3].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Broadcom's Threat Hunter Team published a report on Jewelbug on August 13.
The Broadcom threat intelligence team brought together experts from Symantec and Carbon Black.
Broadcom researchers revealed that Jewelbug, a threat group associated with Chinese-sponsored cyber espionage operations, may be a hacker-for-hire group that also runs profitable crypto fraud campaigns.
Jewelbug is also known as Ink Dragon, Earth Alux, REF770 and CL-STA-0049.
Jewelbug uses the same infrastructure to conduct espionage against governments and militaries across the Middle East, Southeast Asia and South Asia and to run a financially motivated operation targeting Chinese-speaking cryptocurrency users through fake exchange-download portals.
The Broadcom report states: "The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor investigation, no independent verification in cluster
The technical account is specific and internally consistent - named tooling (XG-Web, Antino, VARGEIT/Squidoor/FinalDraft), named access vectors, quantified victim telemetry and a named-persona attribution chain - and the espionage activity is said to have been reported previously by three other research teams. But everything in this cluster traces to one trade-press summary of one Broadcom report: no IOCs, no provenance for the recovered victim database, no third-party confirmation of the espionage/crypto-fraud consolidation, and no response from the named company or its legal representative.
Large documented victim footprint across government and enterprise targets
Read as real-world operational footprint rather than product uptake, the observed scale is substantial: over a million implant check-ins and 580,000+ stolen cookies in under three months, 90+ South Asian police and government email addresses, 15+ government webmail tenants compromised by one script, and implants configured against a major US manufacturer's internal proxy. The counts come from a single vendor-recovered database whose collection method is not described, which caps the score.
Slightly overstated: firm framing on a single unverified vendor assessment
The coverage preserves the vendor's own hedge ('may be a hacker-for-hire group') and stays close to reported detail, so the gap is small. It skews mildly positive because the strongest structural claim - one team, one console, two businesses - and the attribution of a named company and legal representative are presented with vendor-supplied confidence and no independent check, no IOCs, and no comment from the parties named or the affected manufacturer.
Commercial vendor research with visible positioning interest
The findings originate with Broadcom's Threat Hunter Team, an in-house research group formed from Symantec and Carbon Black, which sells security products; publishing a novel, named-actor investigation that collapses two threat categories carries clear marketing and differentiation value. The trade publication's incentives are conventional news interest. The cluster shows no financial disclosure, no sponsor relationship, and no third party with an offsetting stake, so the reading is confined to the vendor's own commercial position.
Moderate: coherent detail, but one publisher relaying one vendor
Confidence is limited by structure rather than by internal inconsistency. The account is granular and quantified, and the espionage half aligns with prior reporting by three other teams, but a single publisher relaying a single vendor report leaves the novel consolidation claim, the database provenance and the named-entity attribution untested. Assessment of the technical tradecraft is more secure than assessment of attribution or motive.
security
Cavern's DNS Coin-Flip: When Google Apps Script Becomes Rotatable C2 Plumbing1 distinct publisher
build
Once the question needs a cube, you own the parser1 distinct publisher
build
Flux moves GitOps' source of truth into registries you own, and mirroring becomes the prerequisite1 distinct publisher
security
Unit 42's Credential Brief: Hunt The Login That Succeeds Right After The Failures1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026