Find notable cyber news and cases, enriched with sources, timelines, and signals.

Jewelbug multi-region government webmail espionage campaign

Campaign
First reported
Last updated
Happening score
H score 55
1 unique sources, 1 articles

Summary

Hide ▲

The Jewelbug campaign compromised 15 government webmail tenants and expanded a multi-region espionage effort against state targets in the Middle East, Southeast Asia, and South Asia. The operation used a shared webmail compromise and malicious script injection to reach login pages and mailbox views, then exfiltrated cookies to an operator C2 server. The same infrastructure also supported parallel cryptocurrency fraud, increasing the scale and operational continuity of the actor’s activity.

Related Happenings

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score60 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

How related: The data showed that the hackers ran a large-scale espionage operation and "an industrial-scale cryptocurrency fraud business."

About this happening: Jewelbug has paired espionage with an industrial-scale cryptocurrency fraud business, turning its operations into a blended actor ecosystem that combines government-ta...

15 Government tenants hit by network compromise

Incident
H score45 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

How related: In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.

About this happening: The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity acr...

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations

Campaign
H score39 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...

Grandoreiro DLL side-loading campaign targeting banks in Portugal

Campaign
H score26 First: 27.05.2026 19:10 Last: 27.05.2026 19:10 Sources 1

About this happening: Grandoreiro is running a new DLL side-loading campaign against banks in Portugal, extending a long-lived banking-malware operation into 2026. The latest wave uses...

Timeline

  1. 13.08.2026 21:15 2 articles · 2h ago

    Jewelbug compromises 15 government webmail tenants across multiple regions

    Initial Disclosure

    Jewelbug, also known as Earth Alux and REF7707, compromised webmail accounts belonging to 15 government tenants after gaining write access to a shared webmail installation on a platform operated by a state telecommunications provider and national services agency. The same operation targeted government and military organizations across the Middle East, Southeast Asia, and South Asia, used a malicious script on login pages and mailbox views to open a WebSocket to the operator C2, and overlapped with parallel cryptocurrency fraud activity run from the same control panel.

    Show sources