A China-based hacker-for-hire group called Jewelbug has been conducting government espionage and cryptocurrency fraud from the same control panel, according to a new report from Broadcom's Symantec and Carbon Black Threat Hunter Team. The operation targets governments and militaries across the Middle East, Southeast Asia, and South Asia for intelligence gathering, while simultaneously running a for-profit scam aimed at Chinese-speaking cryptocurrency users. Both missions run through XG-Web, a browser-based remote-access framework that turns a victim's browser into a complete control channel reaching into the host computer and the internal network behind it.

The espionage campaign's scale is enormous. The operation collected more than one million implant check-in records, over 580,000 stolen browser cookies, several thousand captured credentials, and at least 2,300 exfiltrated email bodies. Server logs recorded roughly 1.1 million geolocation events against about 4,300 distinct source IP addresses. These included approximately 87,200 connections from a Southeast Asian country targeting state telecom and military networks, around 53,100 from a Middle Eastern country across the national carrier's ranges including Starlink-connected addresses in the capital, and about 15,000 from a second Southeast Asian country including government ministry infrastructure. The group's largest espionage operation compromised a web hosting provider to inject JavaScript code into a common webmail installation used by multiple ministries associated with a Middle Eastern government, spanning 15 government webmail tenants. The threat actor's infrastructure also monitored more than 90 police and government email addresses in South Asia.

"What makes Jewelbug notable is the combination of two missions in one set of hands," the report states. Foreign government and military espionage was run from the same infrastructure, by the same team, as a commodity cryptocurrency fraud business. The group has developed five generations of command-and-control code and a family of implants spanning browsers, Windows endpoints, Linux servers, and network devices, all feeding into a single database of victims. At least one of the operators is tied to a registered company based in Hunan Province. That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims.

The financial operation works as a front for an SEO poisoning scheme, according to the researchers. The group operates a registered Chinese company advertising commercial search engine optimization services on Telegram, but it's actually running a scheme involving AI-generated fake pages impersonating OKX and Binance, more than 40 content management servers, and click fraud bots that drive search engines to rank those pages. The primary implant is a malicious browser extension named "PDF Viewer" that runs on both Google Chrome and Mozilla Firefox, requesting permissions to access cookies, the debugger, and native messaging, run scripts, intercept web requests, and monitor downloads across all sites. The extension can run arbitrary JavaScript on any web page, remotely interact with the browser, and harvest credentials by hooking login forms, cookies, browsing history, bookmarks, screenshots, clipboard, and web traffic. The clipboard module functions like a clipper, swapping any copied cryptocurrency wallet address with an attacker's to reroute transactions. The researchers note the pairing of espionage and fraud is the signature of a hack-for-hire entity running for-profit crime on the side, showing the blurring lines between nation-state threat actors and cybercrime groups. For organizations in government and defense sectors, the challenge isn't just detecting advanced intrusion tools—it's recognizing that mercenary operators now treat state espionage and consumer fraud as interchangeable revenue streams managed with the same operational discipline.