Find notable cyber news and cases, enriched with sources, timelines, and signals.

Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud

Threat Actor Meta
First reported
Last updated
Happening score
H score 60
1 unique sources, 1 articles

Summary

Hide ▲

Researchers linked Jewelbug to a single hack-for-hire model, showing that espionage and crypto fraud now share one control panel and shared infrastructure. The cluster's dual-use setup broadens the threat from state-aligned spying to a monetized ecosystem that can harvest access while pursuing profit. The operation is also tracked as Ink Dragon, Earth Alux, REF770 and CL-STA-0049. Its reach spans governments and militaries in the Middle East, Southeast Asia and South Asia.

Related Happenings

Jewelbug crypto fraud campaign targeting Chinese-speaking users

Campaign
H score45 First: 14.08.2026 10:30 Last: 14.08.2026 10:30 Sources 1

How related: “The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan.”

About this happening: The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score60 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug has paired espionage with an industrial-scale cryptocurrency fraud business, turning its operations into a blended actor ecosystem that combines government-ta...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

Red Menshen telecom espionage campaign

Campaign
H score33 First: 26.03.2026 19:40 Last: 26.03.2026 19:40 Sources 1

About this happening: A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...

Timeline

  1. 14.08.2026 10:30 2 articles · 2h ago

    Jewelbug shares XG-Web infrastructure across espionage and crypto fraud

    Initial Disclosure

    Broadcom's Threat Hunter Team disclosed that Jewelbug, also tracked as Ink Dragon, Earth Alux, REF770 and CL-STA-0049, runs a dual-use operation on shared XG-Web infrastructure that combines espionage against governments and militaries in the Middle East, Southeast Asia and South Asia with a crypto-fraud campaign against Chinese-speaking cryptocurrency users. The same ecosystem used vulnerable IIS and SharePoint servers, web shells, VARGEIT, Squidoor or FinalDraft, Antino, ClientKing, a malicious PDF Viewer extension, Microsoft Graph/Outlook APIs, DNS tunnelling, ICMP tunnelling and Google Docs payload delivery.

    Show sources