Broadcom’s Threat Hunter Team, combining Symantec and Carbon Black research, published new findings on August 13 showing that Jewelbug, a China-linked group also tracked as Ink Dragon, Earth Alux, and CL-STA-0049, runs state espionage and cryptocurrency fraud from the same infrastructure rather than as separate operations. The group’s XG-Web control panel logged more than one million implant check-ins and over 580,000 stolen browser cookies in under three months, spanning government and military espionage targets across the Middle East, Southeast Asia, and South Asia alongside fake cryptocurrency exchange portals aimed at Chinese-speaking users.

Why it matters: the finding upends a common defender assumption that state-linked and financially motivated activity come from different teams with different tradecraft. Researchers found the opposite: “The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel.” Jewelbug’s toolset includes the Antino Windows backdoor, a Rust-based Linux and router implant called ClientKing with 37 distinct builds, and a malicious “PDF Viewer” browser extension capable of stealing session tokens and swapping cryptocurrency addresses mid-transaction.

The original insight: a single watering-hole compromise reportedly hit more than 15 government webmail tenants at once, meaning defenders scoping this threat purely as targeted espionage will miss the crypto-fraud infrastructure reusing the same command-and-control, and vice versa. Security teams should treat sightings of either activity pattern, from either angle, as reason to hunt for the other, a pattern also visible in other state-linked infrastructure reuse this year and in the long-dwell email-platform intrusions CyberTech has tracked.

Source: Broadcom (Symantec Threat Hunter Team)