Piece of news of the day
ADVANCED SECURITY EUROPA
EOODCrypto Conundrum: Unveiling the Dual Operations of Cyber Espionage Group Jewelbug
14 August 2026Broadcom's Threat Hunter Team recently disclosed that the Jewelbug threat group, linked to Chinese-sponsored cyber espionage, may also conduct profitable crypto fraud schemes.
The group, also known as Ink Dragon, Earth Alux, etc., targets governments in the Middle East, Southeast Asia, and South Asia, in addition to Chinese-speaking crypto users through fake exchange portals.
Research uncovered shared infrastructure between the espionage and fraud operations, with one operator identified as 'ople500' or 'bubble boss' offering SEO services.
Jewelbug's cyber operations, accessed via vulnerable servers, include backdoors like VARGEIT and C2 methods like DNS tunnelling.
They have targeted governments and stolen email addresses and browser cookies, with one operation compromising a major US company's internal proxy.
Their largest exploit involved watering-hole attacks on multiple Middle Eastern government webmail systems simultaneously.

