Symantec uncovered Jewelbug, a China based hackers for hire group running parallel government espionage and AI driven cryptocurrency fraud from a single command and control panel called XG Web. The espionage campaign compromised over 15 government webmail tenants in the Middle East, targeted Southeast Asian military...
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Symantec's Threat Hunter Team reveal in August 2026 about the China-linked hackers-for-hire group Jewelbug, including how its dual-. Article summary: Now I have the primary source PDF and strong coverage from multiple outlets. Let me compile the answer.. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as
In August 2026, Symantec's Threat Hunter Team published a detailed dossier revealing that Jewelbug (also tracked as Earth Alux, REF7707, CL-STA-0049) is a China-based hackers-for-hire group running parallel government espionage and AI-powered cryptocurrency fraud operations from a single centralized command-and-control panel called XG-Web . The investigation uncovered a sprawling operation that logged over one million implant check-ins, more than 580,000 stolen browser cookies, and over 2,300 exfiltrated email bodies between February and May 2026
.
XG-Web is a three-tier browser-centric C2 panel built with a React frontend, Node.js backend, and MySQL database, using hybrid RSA-2048/AES-256 encryption over WebSocket Secure. The group's own internal documentation drops any pretense of "authorized penetration testing" and describes functions in plain terms: "browser hijacking," "data theft," "man-in-the-middle attack," and silent webcam/microphone listening .
com.microsoft.runedge) 525xiaoxiao was reused as the admin login across a fleet of 44 CMS servers and as a bulk domain registrant The group's recovered victim database logged over one million implant check-ins, more than 580,000 stolen browser cookies, and over 2,300 exfiltrated email bodies between February and May 2026 . This scale highlights how effectively a small hackers-for-hire crew can run simultaneous espionage and fraud operations using shared infrastructure.
Symantec assesses with high confidence that the cryptocurrency fraud arm is run by a named individual — the sole legal representative of a company registered in Changsha County, Hunan Province, China (founded 2019, described as an SEO business). The individual used the handle "paopaodada" (泡泡大大) and advertised a "website ranking rental" service on Telegram against a Binance-branded image. Symantec recovered the operator's real-name government-issued ID verification documents, a business license, and a signed/stamped media-platform authorization letter .
No direct evidence links Jewelbug to the Chinese state, but Symantec notes the targeting — government ministries, military intelligence, a U.S. aerospace manufacturer — makes other explanations unlikely . Whether the same individual operated the espionage campaigns is not established, but both activities shared the same infrastructure, overlapping page-cloaking code, an aligned timeline, and the same XG-Web panel. Symantec assesses it most likely that the SEO business supplied access, delivery, and infrastructure into the espionage operation
.
The group left a significant trail of evidence due to poor opsec :
C:\phpstudy_pro\WWW\), the production path (/data/xg-web/backend/), and a developer LAN address that the implant's own code explicitly excluded from capture.D:\工作软件\vpn最新\ on a Windows NT 10.0.26200 host, with logs showing a working pattern concentrated between 13:00–01:00 UTC+8, routing set to bypass mainland China — consistent with an operator physically inside China.Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Symantec uncovered Jewelbug, a China based hackers for hire group running parallel government espionage and AI driven cryptocurrency fraud from a single command and control panel called XG Web.
Symantec uncovered Jewelbug, a China based hackers for hire group running parallel government espionage and AI driven cryptocurrency fraud from a single command and control panel called XG Web. The espionage campaign compromised over 15 government webmail tenants in the Middle East, targeted Southeast Asian military and police bodies, and hit a U.S.
The crypto fraud used AI generated fake OKX and Binance pages and a malicious browser extension to silently replace wallet addresses; the operation logged over 1 million implant check ins and 580,000 stolen browser co...