Government and Military Entities in the Middle East, Government and Military Entities in Southeast Asia and Government and Military Entities in South Asia: Researchers Link Suspected Chinese APT to Hack-for-Hire Operations

Government and Military Entities in the Middle East, Government and Military Entities in Southeast Asia and Government and Military Entities in South Asia: Researchers Link Suspected Chinese APT to Hack-for-Hire Operations

Jewelbug: Chinese-Linked APT Group Blends Espionage with Crypto Fraud Operations

Security researchers from Broadcom’s Threat Hunter Team (a collaboration between Symantec and Carbon Black) have uncovered new details about Jewelbug, a threat group linked to Chinese-sponsored cyber espionage, revealing that it operates as a hacker-for-hire collective while simultaneously running lucrative cryptocurrency fraud schemes.

In a report published on August 13, researchers confirmed that Jewelbug also tracked as Ink Dragon, Earth Alux, REF770, and CL-STA-0049 uses shared infrastructure and a single control panel for both state-aligned espionage and financially motivated attacks targeting Chinese-speaking crypto users via fake exchange-download portals. The group’s dual operations are managed by the same small team, with at least one operator, "ople500", linked to a "paopaodada" (bubble boss) persona advertised on Telegram for a "website ranking rental" service.

Broadcom traced this individual with high confidence to a Changsha-based SEO company in Hunan province, whose legal representative appears to provide infrastructure and access to Jewelbug’s operations without direct involvement in the attacks.

Espionage Tactics & Targets

Jewelbug’s cyber espionage activities have been documented by multiple security firms, including Trend Micro, Palo Alto Networks’ Unit 42, and Check Point Research. The group typically breaches targets via vulnerable IIS and SharePoint servers, deploying web shells and a sophisticated backdoor (VARGEIT/Squidoor/FinalDraft) that supports stealthy command-and-control (C2) methods, including:

  • Microsoft Graph/Outlook APIs
  • DNS tunneling
  • ICMP tunneling

Broadcom’s investigation uncovered extensive targeting of government and military entities across the Middle East, Southeast Asia, and South Asia, including:

  • Over 90 police and government email addresses in South Asia
  • A victim database logging 1 million+ implant check-ins and 580,000+ stolen browser cookies in under three months
  • A watering-hole attack compromising 15+ government webmail tenants in a single Middle Eastern country
  • Use of an internal proxy belonging to a major U.S. aerospace and industrial manufacturer

The findings highlight Jewelbug’s dual operational model, blending state-backed espionage with criminal profit motives, while leveraging shared resources to maximize efficiency.

Source: https://www.infosecurity-magazine.com/news/researchers-link-chinese-apt-hack/

Government and Military Entities in the Middle East TPRM report: https://www.rankiteo.com/company/bloomberg-government

Government and Military Entities in Southeast Asia TPRM report: https://www.rankiteo.com/company/bloomberg-government

Government and Military Entities in South Asia TPRM report: https://www.rankiteo.com/company/bloomberg-government

"id": "blo1786703490",
"linkid": "bloomberg-government",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "8",
"explanation": "Attack that could bring to a war"
{'affected_entities': [{'customers_affected': '90+ police and government email '
                                              'addresses in South Asia',
                        'industry': ['public sector', 'defense'],
                        'location': ['Middle East',
                                     'Southeast Asia',
                                     'South Asia'],
                        'name': 'Government and military entities',
                        'type': 'government/military'},
                       {'industry': ['aerospace', 'industrial'],
                        'location': 'United States',
                        'name': 'Major U.S. aerospace and industrial '
                                'manufacturer',
                        'type': 'corporation'}],
 'attack_vector': ['vulnerable IIS and SharePoint servers',
                   'web shells',
                   'fake exchange-download portals',
                   'watering-hole attack'],
 'data_breach': {'number_of_records_exposed': ['1 million+ implant check-ins',
                                               '580,000+ stolen browser '
                                               'cookies'],
                 'personally_identifiable_information': 'email addresses',
                 'sensitivity_of_data': 'high',
                 'type_of_data_compromised': ['browser cookies',
                                              'email addresses',
                                              'implant check-ins']},
 'date_publicly_disclosed': '2024-08-13',
 'description': 'Security researchers from Broadcom’s Threat Hunter Team (a '
                'collaboration between Symantec and Carbon Black) have '
                'uncovered new details about Jewelbug, a threat group linked '
                'to Chinese-sponsored cyber espionage, revealing that it '
                'operates as a hacker-for-hire collective while simultaneously '
                'running lucrative cryptocurrency fraud schemes. The group '
                'uses shared infrastructure and a single control panel for '
                'both state-aligned espionage and financially motivated '
                'attacks targeting Chinese-speaking crypto users via fake '
                'exchange-download portals.',
 'impact': {'data_compromised': ['1 million+ implant check-ins',
                                 '580,000+ stolen browser cookies'],
            'identity_theft_risk': 'high',
            'systems_affected': ['government and military email systems',
                                 'webmail tenants',
                                 'internal proxy of a U.S. aerospace and '
                                 'industrial manufacturer']},
 'initial_access_broker': {'backdoors_established': ['web shells',
                                                     'VARGEIT/Squidoor/FinalDraft '
                                                     'backdoor'],
                           'entry_point': ['vulnerable IIS and SharePoint '
                                           'servers'],
                           'high_value_targets': ['government and military '
                                                  'entities',
                                                  'U.S. aerospace and '
                                                  'industrial manufacturer']},
 'investigation_status': 'ongoing',
 'motivation': ['state-sponsored espionage', 'financial gain'],
 'post_incident_analysis': {'root_causes': ['shared infrastructure for '
                                            'espionage and fraud',
                                            'use of vulnerable IIS/SharePoint '
                                            'servers',
                                            'watering-hole attacks']},
 'references': [{'date_accessed': '2024-08-13',
                 'source': 'Broadcom’s Threat Hunter Team'},
                {'source': 'Trend Micro'},
                {'source': 'Palo Alto Networks’ Unit 42'},
                {'source': 'Check Point Research'}],
 'response': {'third_party_assistance': 'Broadcom’s Threat Hunter Team '
                                        '(Symantec and Carbon Black)'},
 'threat_actor': 'Jewelbug (also known as Ink Dragon, Earth Alux, REF770, '
                 'CL-STA-0049)',
 'title': 'Jewelbug: Chinese-Linked APT Group Blends Espionage with Crypto '
          'Fraud Operations',
 'type': ['cyber espionage', 'cryptocurrency fraud'],
 'vulnerability_exploited': ['IIS vulnerabilities',
                             'SharePoint vulnerabilities']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.