Jewelbug Hackers Breach Government Webmail and Run Crypto Fraud on Shared Infrastructure
A threat actor tracked as Jewelbug has compromised government webmail systems by injecting malicious JavaScript into a shared hosting provider, affecting more than 15 webmail tenants, according to a Symantec Threat Hunter Team report published on August 13, 2026. The injected scripts steal session cookies via WebSocket connections and serve fake Adobe Flash update prompts to Windows users on targeted government domains. Victims who execute the fake installer receive the Antino malware, which abuses the Microsoft Graph API for command-and-control and deploys a rogue browser extension capable of stealing cookies, browsing history, screenshots, and clipboard data. On Linux systems and ASUS routers, the group deploys a Rust-based implant called ClientKing alongside a kernel rootkit and a credential-harvesting authentication module. Separately, the same XG-Web infrastructure is used to operate AI-generated fake cryptocurrency exchange pages impersonating platforms such as OKX and Binance, though the precise organisational link between the espionage and fraud operations has not been publicly confirmed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in