XG-Web is a three-tier browser-centric C2 panel built with a React frontend, Node.js backend, and MySQL database, using hybrid RSA-2048/AES-256 encryption over WebSocket Secure. The group's own internal documentation drops any pretense of "authorized penetration testing" and describes functions in plain terms: "browser hijacking," "data theft," "man-in-the-middle attack," and silent webcam/microphone listening .
com.microsoft.runedge) 525xiaoxiao was reused as the admin login across a fleet of 44 CMS servers and as a bulk domain registrant The group's recovered victim database logged over one million implant check-ins, more than 580,000 stolen browser cookies, and over 2,300 exfiltrated email bodies between February and May 2026 . This scale highlights how effectively a small hackers-for-hire crew can run simultaneous espionage and fraud operations using shared infrastructure.
Symantec assesses with high confidence that the cryptocurrency fraud arm is run by a named individual — the sole legal representative of a company registered in Changsha County, Hunan Province, China (founded 2019, described as an SEO business). The individual used the handle "paopaodada" (泡泡大大) and advertised a "website ranking rental" service on Telegram against a Binance-branded image. Symantec recovered the operator's real-name government-issued ID verification documents, a business license, and a signed/stamped media-platform authorization letter .
No direct evidence links Jewelbug to the Chinese state, but Symantec notes the targeting — government ministries, military intelligence, a U.S. aerospace manufacturer — makes other explanations unlikely . Whether the same individual operated the espionage campaigns is not established, but both activities shared the same infrastructure, overlapping page-cloaking code, an aligned timeline, and the same XG-Web panel. Symantec assesses it most likely that the SEO business supplied access, delivery, and infrastructure into the espionage operation
.
C:\phpstudy_pro\WWW\), the production path (/data/xg-web/backend/), and a developer LAN address that the implant's own code explicitly excluded from capture.D:\工作软件\vpn最新\ on a Windows NT 10.0.26200 host, with logs showing a working pattern concentrated between 13:00–01:00 UTC+8, routing set to bypass mainland China — consistent with an operator physically inside China.