Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
North Korean IT Workers Impersonate Employees Using Forged IDs
August 13, 2026
CISA Warns of Critical Windows Ancillary Function Driver Zero-Day Exploited in Attacks
August 13, 2026
Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations
August 13, 2026
Home/CyberSecurity News/Jewelbug APT Hijacks Browsers to Steal Cookies, Spy on Government Networks
CyberSecurity News

Jewelbug APT Hijacks Browsers to Steal Cookies, Spy on Government Networks

Key Takeaways The China-linked APT group, Jewelbug, has been observed hijacking web browsers to conduct espionage and cryptocurrency fraud. The group targeted government webmail systems in the Middle...

David kimber
David kimber
August 13, 2026 5 Min Read
3 0

Key Takeaways

  • The China-linked APT group, Jewelbug, has been observed hijacking web browsers to conduct espionage and cryptocurrency fraud.
  • The group targeted government webmail systems in the Middle East, Southeast Asia, and South Asia, compromising over 15 government webmail tenants in a single incident.
  • Jewelbug utilized a sophisticated browser-focused control system, XG-Web, alongside malicious Chrome and Firefox extensions disguised as “PDF Viewer” to steal cookies, credentials, and sensitive data.
  • The operation harvested over 580,000 browser cookies, thousands of credentials, and more than 2,300 email bodies, demonstrating a significant data breach.
  • Defenders should prioritize reviewing browser extensions, monitoring webmail templates for unauthorized scripts, and implementing robust multi-factor authentication.

A sophisticated China-based advanced persistent threat (APT) group, identified as Jewelbug, has been exploiting common web browsing activities to infiltrate government networks and engage in cryptocurrency fraud. The group’s tactics involve compromising government webmail systems, stealing browser cookies, and leveraging this access to monitor internal network activities.

Table Of Content

  • Key Takeaways
  • Jewelbug APT Hijacks Browsers
  • Watering Holes Put Government Networks at Risk
  • What You Should Do

Jewelbug’s campaigns have spanned government ministries and various targets across the Middle East, Southeast Asia, and South Asia. A notable incident involved the deployment of a malicious script across more than 15 government webmail tenants, creating a direct pathway for attackers to access officials’ accounts.

Analysts at Symantec have characterized Jewelbug as a “hackers-for-hire” operation, uniquely blending state-sponsored espionage with financially motivated cybercrime. According to Symantec said in a report, the same operational team, infrastructure, and command-and-control (C2) panel are utilized for both intelligence gathering and cryptocurrency fraud, indicating a blurring of lines between these distinct objectives.

The sheer scale of Jewelbug’s activities is alarming. Investigators have uncovered over one million implant check-ins, more than 580,000 stolen browser cookies, thousands of compromised credentials, and over 2,300 intercepted email bodies. This level of access can expose highly sensitive communications and enable attackers to deepen their foothold within targeted networks.

Jewelbug APT Hijacks Browsers

At the core of Jewelbug’s operations is XG-Web, a browser-centric control system that grants operators remote command over infected browsers. A key component of this system is a malicious Chrome and Firefox extension, masquerading as a “PDF Viewer.” This extension, while appearing to be a benign document reader, demands extensive permissions far beyond its stated purpose.

Upon installation, the rogue extension gains the ability to read browser cookies, detect new session tokens, examine browsing history and bookmarks, capture screenshots, and harvest clipboard contents. The theft of browser cookies is particularly dangerous as it allows threat actors to hijack active user sessions, bypassing multi-factor authentication (MFA) mechanisms.

The extension also injects malicious code into websites and intercepts browser traffic. It communicates with a Windows helper process named “com.microsoft.runedge,” which is designed to mimic a legitimate Microsoft Edge component, allowing it to execute commands on the compromised device. This highlights the significant risks posed by malicious browser extensions, which can serve as critical entry points for account compromise.

In conjunction with browser access, the group deploys its Antino backdoor. Victims are often lured into downloading this malware through fake Adobe Flash or Adobe installer prompts encountered during compromised webmail sessions. Antino leverages Microsoft Graph API traffic for its command and control operations, while the malicious browser extension provides a constant stream of the victim’s online activities.

Jewelbug further expands its reach with ClientKing, a Linux and router implant. This tool allows the APT group to move beyond initial browser compromises and establish persistence within servers and network equipment, enabling broader infiltration of the target environment.

Watering Holes Put Government Networks at Risk

One of Jewelbug’s most extensive campaigns involved a watering-hole attack targeting a shared government webmail platform in the Middle East. Instead of individually attacking each ministry, the group injected a malicious script directly into the shared hosting environment. This allowed them to redirect users visiting affected login and mailbox pages to attacker-controlled infrastructure.

This watering-hole strategy proves highly effective because it exploits the trust users place in legitimate services. Similar government watering hole incidents demonstrate how compromising a widely used public site can expose high-value targets without the need for traditional phishing emails.

The injected script was designed to collect cookies and identify users via their government email addresses. Subsequently, it would display a deceptive software update prompt, specifically targeting selected Windows users within the compromised domains. In one instance, operators successfully captured authenticated traffic to a virtualization management service, providing clear evidence that browser compromise had evolved into a gateway to critical internal infrastructure.

In parallel to its espionage efforts, Jewelbug maintains a cryptocurrency fraud operation. This side of their activity involves creating fake cryptocurrency exchange download pages and manipulating search engine results to attract Chinese-speaking victims. The interconnection between these two distinct operations is crucial, as shared infrastructure allows the financially driven schemes to potentially fund and support the group’s espionage objectives, much like other APT operations that employ multiple access vectors against government targets.

What You Should Do

  • Review Browser Extensions: Regularly audit and remove any unknown or suspicious browser extensions. Grant extensions only the minimum necessary permissions.
  • Enable Multi-Factor Authentication (MFA): While cookie theft can bypass some MFA, it significantly increases the barrier for attackers. Implement strong, phishing-resistant MFA methods where possible.
  • Monitor Webmail Templates: Government and enterprise IT teams should rigorously inspect webmail login and mailbox templates for any unauthorized scripts or modifications.
  • Rotate Credentials and Sessions: In the event of a suspected compromise, immediately rotate all exposed credentials and invalidate active user sessions.
  • Network Segmentation: Segment critical administration systems and sensitive data from general user networks to limit lateral movement in case of a breach.
  • Monitor Unusual Network Requests: Implement robust network monitoring to detect unusual requests to internal services, especially those originating from user endpoints.
  • Prompt Patching and Updates: Ensure all operating systems, browsers, and third-party software are kept up-to-date with the latest security patches.
  • Review Third-Party Hosting Access: Regularly audit access permissions and security configurations for any third-party hosting providers used for critical services like webmail.
  • User Education: Educate users about the dangers of suspicious browser extensions, fake software update prompts, and the importance of verifying download sources.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerPatchSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

GitLab 16.2.2 Patches High-Severity XSS and CI/CD Authorization Flaws

Next Post

Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Vulnerability in Schneider Electric APC NetBotz Exposes Data Centers
August 13, 2026
Threat Actors Exploit Google Workspace for Phishing and Scam Campaigns
August 13, 2026
Critical Microsoft SharePoint CVE-2023-29357 Actively Exploited
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us