Jewelbug APT Exploits Browser Extensions for Espionage and Cybercrime
A China-based threat group, Jewelbug, has transformed routine web browsing into a vector for cyber espionage and financial fraud, targeting government entities across the Middle East, Southeast Asia, and South Asia. According to a Symantec report, the group operates as a hackers-for-hire collective, blending state-sponsored surveillance with cryptocurrency theft.
Key Attack Methods
Jewelbug’s campaigns centered on browser-based infiltration, leveraging a malicious Chrome/Firefox extension dubbed "PDF Viewer". Disguised as a document reader, the extension requested excessive permissions, enabling attackers to:
- Steal browser cookies (over 580,000 captured)
- Harvest credentials (thousands compromised)
- Monitor browsing history, bookmarks, and clipboard contents
- Take screenshots and intercept browser traffic
Stolen cookies allowed attackers to bypass multi-factor authentication (MFA) by hijacking active sessions. The extension communicated with a Windows helper tool (com.microsoft.runedge), masquerading as a legitimate Microsoft Edge component to execute commands.
Watering-Hole Attacks on Government Webmail
Jewelbug’s most significant campaign targeted a shared government webmail platform in the Middle East, compromising over 15 tenants. Instead of attacking ministries individually, the group embedded a malicious script in the hosting environment. When officials accessed login or mailbox pages, the script:
- Collected cookies and identified users via government email addresses
- Triggered fake software update prompts for selected Windows users
- Redirected victims to attacker-controlled infrastructure
This watering-hole tactic exploited trust in official services, allowing the group to capture authenticated traffic including access to a virtualization-management service without relying on phishing emails.
Dual Espionage and Fraud Operations
Jewelbug’s infrastructure supported both espionage and financial crime, with shared tools and control panels. Alongside government targeting, the group ran cryptocurrency fraud schemes, using:
- Fake exchange download pages
- Search-result manipulation to lure Chinese-speaking victims
The group’s Antino backdoor distributed via fake Adobe Flash/Installer downloads used Microsoft Graph API traffic for command-and-control (C2). Meanwhile, ClientKing, a Linux/router implant, extended access beyond browsers to servers and network equipment.
Scale and Impact
Symantec’s investigation uncovered:
- Over 1 million implant check-ins
- 2,300+ stolen email bodies
- Thousands of compromised credentials
The overlap between state-aligned espionage and profit-driven crime highlights how threat actors leverage shared infrastructure to maximize impact.
Indicators of Compromise (IoCs)
Key artifacts include:
- Malicious domains (e.g., fonts[.]tarotfree101[.]top, microsoft-flash[.]com)
- C2 IP addresses (e.g., 103[.]87[.]9[.]62, 47[.]84[.]37[.]113)
- SHA-256 hashes of backdoors and lures (e.g., e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf)
The campaign underscores the risks of malicious browser extensions and compromised webmail platforms as entry points for high-level intrusions.
Source: https://cybersecuritynews.com/jewelbug-apt-hijacks-browsers/
PwC Middle East cybersecurity rating report: https://www.rankiteo.com/company/pwc-middle-east
"id": "PWC1786625802",
"linkid": "pwc-middle-east",
"type": "Cyber Attack",
"date": "1/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Public Sector',
'location': ['Middle East',
'Southeast Asia',
'South Asia'],
'type': 'Government Entities'},
{'industry': 'Finance',
'location': 'Chinese-speaking regions',
'type': 'Cryptocurrency Users'}],
'attack_vector': ['Malicious Browser Extension',
'Watering-Hole Attack',
'Fake Software Updates'],
'data_breach': {'data_exfiltration': True,
'number_of_records_exposed': ['580,000+ cookies',
'2,300+ email bodies',
'Thousands of credentials'],
'personally_identifiable_information': True,
'sensitivity_of_data': 'High (Government communications, PII)',
'type_of_data_compromised': ['Browser Cookies',
'Credentials',
'Email Bodies',
'Browsing History',
'Bookmarks',
'Clipboard Contents',
'Screenshots']},
'description': 'A China-based threat group, Jewelbug, has transformed routine '
'web browsing into a vector for cyber espionage and financial '
'fraud, targeting government entities across the Middle East, '
'Southeast Asia, and South Asia. The group operates as a '
'hackers-for-hire collective, blending state-sponsored '
'surveillance with cryptocurrency theft. The campaign '
"leveraged a malicious Chrome/Firefox extension ('PDF Viewer') "
'to steal browser cookies, harvest credentials, monitor '
'browsing activity, and bypass MFA. The group also conducted '
'watering-hole attacks on a shared government webmail '
'platform, compromising over 15 tenants and capturing '
'authenticated traffic.',
'impact': {'data_compromised': ['580,000+ browser cookies',
'Thousands of credentials',
'2,300+ email bodies'],
'identity_theft_risk': ['High (PII exposure)'],
'operational_impact': ['Compromised government communications',
'Unauthorized access to '
'virtualization-management services'],
'systems_affected': ['Government webmail platforms',
'Windows systems',
'Linux/Router infrastructure']},
'initial_access_broker': {'backdoors_established': ['Antino Backdoor',
'ClientKing Implant'],
'entry_point': ['Malicious Browser Extension',
'Watering-Hole Attack'],
'high_value_targets': ['Government officials',
'Virtualization-management '
'services']},
'investigation_status': 'Ongoing (Symantec investigation)',
'lessons_learned': 'The incident underscores the risks of malicious browser '
'extensions and compromised webmail platforms as entry '
'points for high-level intrusions. Shared infrastructure '
'can be leveraged for both espionage and financial crime.',
'motivation': ['State-Sponsored Espionage', 'Financial Gain'],
'post_incident_analysis': {'corrective_actions': ['Remove malicious '
'extensions',
'Rotate compromised '
'credentials',
'Implement MFA with '
'phishing-resistant methods',
'Deploy behavioral '
'analytics for session '
'monitoring'],
'root_causes': ['Exploitation of excessive browser '
'extension permissions',
'Compromised government webmail '
'platform',
'Lack of monitoring for session '
'hijacking']},
'recommendations': ['Audit and restrict browser extension permissions',
'Monitor for unusual session activity (e.g., cookie '
'theft)',
'Implement network segmentation to limit lateral movement',
'Enhance monitoring of government webmail platforms',
'Educate users on fake software update risks'],
'references': [{'source': 'Symantec Report'}],
'response': {'third_party_assistance': 'Symantec (Threat Intelligence)'},
'threat_actor': 'Jewelbug (China-based APT group)',
'title': 'Jewelbug APT Exploits Browser Extensions for Espionage and '
'Cybercrime',
'type': ['Espionage', 'Cybercrime', 'Financial Fraud'],
'vulnerability_exploited': ['Excessive Browser Extension Permissions',
'Session Hijacking via Stolen Cookies',
'MFA Bypass']}