Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
Summary
Hide ▲
Show ▼
Jewelbug has paired espionage with an industrial-scale cryptocurrency fraud business, turning its operations into a blended actor ecosystem that combines government-targeting intrusions with monetized fraud infrastructure.
Related Happenings
Jewelbug multi-region government webmail espionage campaign
Campaign
H score55
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
How related:
Jewelbug targeted government and military organizations across the Middle East, Southeast Asia, and South Asia.
About this happening:
The Jewelbug campaign compromised 15 government webmail tenants and expanded a multi-region espionage effort against state targets in the Middle East, Southeast Asia...
Jewelbug multi-region government webmail espionage campaign
CampaignHow related: Jewelbug targeted government and military organizations across the Middle East, Southeast Asia, and South Asia.
About this happening: The Jewelbug campaign compromised 15 government webmail tenants and expanded a multi-region espionage effort against state targets in the Middle East, Southeast Asia...
15 Government tenants hit by network compromise
Incident
H score45
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
How related:
In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.
About this happening:
The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity acr...
15 Government tenants hit by network compromise
IncidentHow related: In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.
About this happening: The 15 government tenants using a shared webmail installation suffered a webmail compromise that let attackers obtain write access and monitor mailbox activity acr...
U.S. Scam Center Strike Force anti-fraud initiative
Public Sector Action
H score50
First: 04.06.2026 09:06
Last: 04.06.2026 09:06
Sources 1
About this happening:
The U.S. government continued Scam Center Strike Force, an ongoing anti-fraud initiative aimed at dismantling cyber-enabled fraud and pig butchering networks targe...
U.S. Scam Center Strike Force anti-fraud initiative
Public Sector ActionAbout this happening: The U.S. government continued Scam Center Strike Force, an ongoing anti-fraud initiative aimed at dismantling cyber-enabled fraud and pig butchering networks targe...
Approval phishing crypto wallet fraud campaign
Campaign
H score41
First: 13.04.2026 11:00
Last: 13.04.2026 11:00
Sources 1
About this happening:
Approval phishing fraud networks were identified at scale, with more than 20,000 victims and at least $33m in additional stolen crypto tied to the operation. The fraud...
Approval phishing crypto wallet fraud campaign
CampaignAbout this happening: Approval phishing fraud networks were identified at scale, with more than 20,000 victims and at least $33m in additional stolen crypto tied to the operation. The fraud...
Record crypto-fraud losses rise with AI-driven impersonation
Trend
H score43
First: 14.01.2026 12:00
Last: 14.01.2026 12:00
Sources 1
About this happening:
Cryptocurrency fraud is surging as scammers use AI chatbots and brand impersonation to widen victim reach and raise payout sizes. A Malwarebytes Labs analysis foun...
Record crypto-fraud losses rise with AI-driven impersonation
TrendAbout this happening: Cryptocurrency fraud is surging as scammers use AI chatbots and brand impersonation to widen victim reach and raise payout sizes. A Malwarebytes Labs analysis foun...
Timeline
-
13.08.2026 21:15 2 articles · 2h ago
Jewelbug runs espionage and crypto-fraud operations against government targets
Campaign Scope UpdateJewelbug, also known as Earth Alux and REF7707, combines espionage against government and military organizations with cryptocurrency fraud. The group is described as using a shared control panel for both activity sets, along with AI-generated fake crypto pages, click bots, and a 44-server content-management fleet with lookalike OKX and Binance domains.
Show sources
- Hackers breach govt webmail while running parallel crypto fraud — www.bleepingcomputer.com — 13.08.2026 21:15
- Hackers breach govt webmail while running parallel crypto fraud — www.bleepingcomputer.com — 13.08.2026 21:15