Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
Summary
Hide ▲
Show ▼
Researchers linked Jewelbug to a single hack-for-hire model, showing that espionage and crypto fraud now share one control panel and shared infrastructure. The cluster's dual-use setup broadens the threat from state-aligned spying to a monetized ecosystem that can harvest access while pursuing profit. The operation is also tracked as Ink Dragon, Earth Alux, REF770 and CL-STA-0049. Its reach spans governments and militaries in the Middle East, Southeast Asia and South Asia.
Related Happenings
Jewelbug crypto fraud campaign targeting Chinese-speaking users
Campaign
H score45
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
How related:
“The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan.”
About this happening:
The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...
Jewelbug crypto fraud campaign targeting Chinese-speaking users
CampaignHow related: “The Broadcom researchers said the group operated a financially motivated campaign targeting Chinese-speaking cryptocurrency users through fake exchange-download websites, while decoy documents themed around Taiwanese government organizations suggested it also had an interest in Taiwan.”
About this happening: The Jewelbug operation ran a financially motivated crypto fraud campaign against Chinese-speaking cryptocurrency users through fake exchange-download websites, bro...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score60
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug has paired espionage with an industrial-scale cryptocurrency fraud business, turning its operations into a blended actor ecosystem that combines government-ta...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug has paired espionage with an industrial-scale cryptocurrency fraud business, turning its operations into a blended actor ecosystem that combines government-ta...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Red Menshen telecom espionage campaign
Campaign
H score33
First: 26.03.2026 19:40
Last: 26.03.2026 19:40
Sources 1
About this happening:
A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...
Red Menshen telecom espionage campaign
CampaignAbout this happening: A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...
Timeline
-
14.08.2026 10:30 2 articles · 2h ago
Jewelbug shares XG-Web infrastructure across espionage and crypto fraud
Initial DisclosureBroadcom's Threat Hunter Team disclosed that Jewelbug, also tracked as Ink Dragon, Earth Alux, REF770 and CL-STA-0049, runs a dual-use operation on shared XG-Web infrastructure that combines espionage against governments and militaries in the Middle East, Southeast Asia and South Asia with a crypto-fraud campaign against Chinese-speaking cryptocurrency users. The same ecosystem used vulnerable IIS and SharePoint servers, web shells, VARGEIT, Squidoor or FinalDraft, Antino, ClientKing, a malicious PDF Viewer extension, Microsoft Graph/Outlook APIs, DNS tunnelling, ICMP tunnelling and Google Docs payload delivery.
Show sources
- Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations — www.infosecurity-magazine.com — 14.08.2026 10:30
- Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations — www.infosecurity-magazine.com — 14.08.2026 10:30