China-Linked Jewelbug Blends Espionage With Crypto Fraud
Jewelbug, a China-linked hacking group, has been tied to both state-oriented cyber espionage and cryptocurrency fraud targeting government organizations and digital-asset users. The overlap matters because the group appears to use shared infrastructure for intelligence gathering and financially motivated crime, blurring conventional distinctions between state-backed operations and profit-seeking scams while making attribution and threat tracking more difficult.
Symantec said its latest investigation found Jewelbug using common command-and-control platforms and servers across the two operations. The hackers deployed malicious browser extensions to steal account credentials and created fraudulent websites impersonating major cryptocurrency exchanges including OKX and Binance. The available report did not specify the exact attack dates, number of victims or financial losses, leaving the scale and duration of the campaign unclear.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →