Hackers breach govt webmail while running parallel crypto fraud
AI Summary
The China-based threat actor Jewelbug (also known as Earth Alux and REF7707) has been conducting espionage operations against government and military organizations in the Middle East, Southeast Asia, and South Asia, while simultaneously running a large-scale cryptocurrency fraud operation. The group compromised a shared webmail platform used by multiple government tenants, injecting a malicious script into login and mailbox pages to steal cookies and credentials. Successful compromises led to the deployment of the Antino backdoor via fake Adobe Flash installers, enabling further payload delivery, including a malicious browser extension called 'PDF Viewer' that steals credentials and injects JavaScript. Symantec uncovered the group's infrastructure, revealing over one million implant check-ins, more than 580,000 stolen browser cookies, and extensive cryptocurrency fraud operations using AI-generated content and lookalike domains impersonating Binance and OKX.
AI-extracted · verify before operational use