Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Cryptocurrency Scams

China-Linked Jewelbug Blends Espionage With Crypto Fraud

1 reports · First detected 2026-08-14 · Last active 2026-08-14

Jewelbug, a China-linked hacking group, has been tied to both state-oriented cyber espionage and cryptocurrency fraud targeting government organizations and digital-asset users. The overlap matters because the group appears to use shared infrastructure for intelligence gathering and financially motivated crime, blurring conventional distinctions between state-backed operations and profit-seeking scams while making attribution and threat tracking more difficult.

Symantec said its latest investigation found Jewelbug using common command-and-control platforms and servers across the two operations. The hackers deployed malicious browser extensions to steal account credentials and created fraudulent websites impersonating major cryptocurrency exchanges including OKX and Binance. The available report did not specify the exact attack dates, number of victims or financial losses, leaving the scale and duration of the campaign unclear.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)