bleeping-computer · Crawled Aug 13, 2026

Hackers breach govt webmail while running parallel crypto fraud

2 IoCs 2 Actors
Read original article ↗

AI Summary

The China-based threat actor Jewelbug (also known as Earth Alux and REF7707) has been conducting espionage operations against government and military organizations in the Middle East, Southeast Asia, and South Asia, while simultaneously running a large-scale cryptocurrency fraud operation. The group compromised a shared webmail platform used by multiple government tenants, injecting a malicious script into login and mailbox pages to steal cookies and credentials. Successful compromises led to the deployment of the Antino backdoor via fake Adobe Flash installers, enabling further payload delivery, including a malicious browser extension called 'PDF Viewer' that steals credentials and injects JavaScript. Symantec uncovered the group's infrastructure, revealing over one million implant check-ins, more than 580,000 stolen browser cookies, and extensive cryptocurrency fraud operations using AI-generated content and lookalike domains impersonating Binance and OKX.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 2 extracted

Type Value Detail
Domain okx[.]com Details →
Domain binance[.]com Details →

MITRE ATT&CK TTPs 1 techniques