Cyber Security News

Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks

Jewelbug has turned ordinary web browsing into an entry point for espionage. The China-based group compromised government webmail systems, stole browser cookies, and used that access to watch activity inside affected networks.

Its campaigns reached ministries and targets across the Middle East, Southeast Asia, and South Asia.

In one major incident, a malicious script was placed across more than 15 government webmail tenants, giving attackers a path to officials’ accounts.

Analysts from Symantec identified Jewelbug as a hackers-for-hire operation that combines government spying with cryptocurrency fraud.

Symantec said in a report shared with Cyber Security News (CSN) that the same team, infrastructure, and control panel supported both missions, blurring targeted intelligence collection and profit-driven crime.

Control panel (Source – Symantec)

The scale is striking. Investigators found more than one million implant check-ins, over 580,000 stolen browser cookies, thousands of captured credentials, and more than 2,300 stolen email bodies.

Such access can expose sensitive correspondence and help attackers move deeper into a network.

Jewelbug APT Hijacks Browsers

At the centre of the activity is XG-Web, a browser-focused control system that lets operators remotely direct an infected browser.

Its main lure was a malicious Chrome and Firefox extension called “PDF Viewer,” presented as a document reader while requesting access far beyond what such an extension needs.

Once installed, the extension could read cookies, watch for new session tokens, inspect browsing history and bookmarks, take screenshots, and capture clipboard contents.

The XG-Web operator panel (Source – Symantec)

Stolen cookies can let criminals reuse a logged-in session, which is why browser cookie theft risks remain serious even where an account uses multi-factor authentication.

The extension also injected code into websites and intercepted browser traffic. It communicated with a Windows helper called com.microsoft.runedge, masquerading as an Edge component, to run commands on the device.

This reflects the wider danger of malicious browser extension campaigns, where a small add-on can become a route to account theft.

The group paired this browser access with its Antino backdoor. Victims saw fake Adobe Flash or Adobe installer downloads during a compromised webmail visit.

Antino then used Microsoft Graph API traffic for command and control, while the extension supplied a view into online activity.

Jewelbug also used ClientKing, a Linux and router implant capable of reaching servers and network equipment. That gave the operation a way to expand beyond a browser foothold and into the surrounding environment.

Watering Holes Put Government Networks at Risk

Jewelbug’s largest campaign targeted a shared government webmail platform in the Middle East.

Rather than attack each ministry separately, the group added a script to a hosting environment. Visitors to affected login and mailbox pages could then be connected to attacker-controlled infrastructure.

A lure document impersonating the CSIS Indo-Pacific Forecast 2026 event page (Source – Symantec)

This approach, known as a watering-hole attack, is effective because people encounter the trap while using a trusted service.

Similar government watering hole incidents show how a compromised public site can expose high-value users without relying on a suspicious email.

The script collected cookies and identified users through government email addresses. It then displayed a fake update prompt only to selected Windows users in targeted domains.

On one system, operators captured authenticated traffic to a virtualisation-management service, evidence that browser theft had become a bridge into internal infrastructure.

Jewelbug also ran a fraud operation that used fake cryptocurrency exchange download pages and search-result manipulation to attract Chinese-speaking victims.

The overlap matters because shared infrastructure can allow a money-making scheme to support espionage, much like APT operations targeting governments that use several access methods.

Defenders should review browser extensions, remove unknown add-ons, investigate native-messaging registrations, and watch for fake software-update prompts.

Agencies should check webmail templates for unauthorized scripts, rotate exposed sessions and credentials, segment administration systems, and monitor unusual requests to internal services.

Prompt patching and review of third-party hosting access can reduce the chance that one compromised platform becomes an exposure.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
SHA-256e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcfHTA lure document
SHA-25601b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31aHTA downloader, Russia/Venezuela/Ukraine lure
SHA-256e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34HTA lure document
SHA-256f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8TEST.hta
SHA-256e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530slc.dll
SHA-256e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bbVb0c44dfslc.dll.wx
SHA-256b09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cffAntino backdoor
SHA-256c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42ccAntino backdoor
SHA-256b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85eflashcenter_pp_ax_install_en.exe
SHA-2560c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bdAntino sample connecting to Microsoft Graph API
SHA-2569b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3Adobe_installer (1).exe
SHA-256153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94eAntino-related sample on infected Middle Eastern host
SHA-256297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561Antino-related sample on infected Middle Eastern host
SHA-25630f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61dAntino-related sample on infected Middle Eastern host
SHA-256430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55Antino-related sample on infected Middle Eastern host
SHA-2565ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97efAntino-related sample on infected Middle Eastern host
SHA-2565edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7acAntino-related sample on infected Middle Eastern host
SHA-2566d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2Antino-related sample on infected Middle Eastern host
SHA-25697c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aadAntino-related sample on infected Middle Eastern host
SHA-256ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813Antino-related sample on infected Middle Eastern host
SHA-256e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0Antino-related sample on infected Middle Eastern host
SHA-256ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877Antino-related sample on infected Middle Eastern host
SHA-256ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869Antino-related sample on infected Middle Eastern host
Domainfonts[.]tarotfree101[.]topCommand-and-control infrastructure
Domainfonts[.]chrorne[.]comTyposquatted payload-hosting domain
Domainrobot[.]avbliud[.]comCommand-and-control infrastructure
Domainmicrosoft-flash[.]comMalicious download infrastructure
Domainwww[.]wps-cn[.]comCommand-and-control infrastructure
Domainwww[.]f1ash[.]org[.]cnMalicious download infrastructure
Domainbrowser-update[.]pages[.]devCommand-and-control infrastructure
Domaineastus2[.]wac-azure[.]comCommand-and-control infrastructure
Domainmailbycloud[.]comCommand-and-control infrastructure
Domainwww[.]jkskhei[.]comCommand-and-control infrastructure
Domainns1[.]jkskhei[.]comCommand-and-control infrastructure
Domaindns[.]wizkidblogger[.]comCommand-and-control infrastructure
Domainr6fi2yvqql[.]execute-api[.]ap-southeast-2[.]amazonaws[.]comCommand-and-control infrastructure
IP address103[.]87[.]9[.]62Network indicator
IP address152[.]42[.]174[.]15Network indicator
IP address143[.]246[.]208[.]236Network indicator
IP address43[.]246[.]208[.]179Network indicator
IP address47[.]84[.]37[.]113Network indicator
IP address47[.]84[.]51[.]173Network indicator
IP address167[.]71[.]195[.]255Network indicator
IP address38[.]12[.]1[.]47Network indicator
IP address129[.]212[.]237[.]224Network indicator
IP address47[.]87[.]71[.]167Network indicator
IP address47[.]250[.]208[.]35Network indicator
IP address219[.]76[.]254[.]184Network indicator
URLhxxp://d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA.logPayload or log-delivery URL
URLhxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc.dll.iwqMalicious DLL URL
URLhxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exeAntino download URL
URLhxxps://www[.]f1ash[.]org[.]cn/flashcenter_pp_ax_install_cn.exeMalicious download URL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

4 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

9 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

14 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

20 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

31 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago