Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
Jewelbug has turned ordinary web browsing into an entry point for espionage. The China-based group compromised government webmail systems, stole browser cookies, and used that access to watch activity inside affected networks. Its campaigns reached ministries and targets across the Middle East, Southeast Asia, and South Asia. In one major incident, a malicious script was […] The post Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks appeared first on Cyber Security Ne
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks
By Tushar Subhra Dutta
August 13, 2026
Jewelbug has turned ordinary web browsing into an entry point for espionage. The China-based group compromised government webmail systems, stole browser cookies, and used that access to watch activity inside affected networks.
Its campaigns reached ministries and targets across the Middle East, Southeast Asia, and South Asia.
In one major incident, a malicious script was placed across more than 15 government webmail tenants, giving attackers a path to officials’ accounts.
Analysts from Symantec identified Jewelbug as a hackers-for-hire operation that combines government spying with cryptocurrency fraud.
Symantec said in a report shared with Cyber Security News (CSN) that the same team, infrastructure, and control panel supported both missions, blurring targeted intelligence collection and profit-driven crime.
Control panel (Source – Symantec)
The scale is striking. Investigators found more than one million implant check-ins, over 580,000 stolen browser cookies, thousands of captured credentials, and more than 2,300 stolen email bodies.
Such access can expose sensitive correspondence and help attackers move deeper into a network.
Jewelbug APT Hijacks Browsers
At the centre of the activity is XG-Web, a browser-focused control system that lets operators remotely direct an infected browser.
Its main lure was a malicious Chrome and Firefox extension called “PDF Viewer,” presented as a document reader while requesting access far beyond what such an extension needs.
Once installed, the extension could read cookies, watch for new session tokens, inspect browsing history and bookmarks, take screenshots, and capture clipboard contents.
The XG-Web operator panel (Source – Symantec)
Stolen cookies can let criminals reuse a logged-in session, which is why browser cookie theft risks remain serious even where an account uses multi-factor authentication.
The extension also injected code into websites and intercepted browser traffic. It communicated with a Windows helper called com.microsoft.runedge, masquerading as an Edge component, to run commands on the device.
This reflects the wider danger of malicious browser extension campaigns, where a small add-on can become a route to account theft.
The group paired this browser access with its Antino backdoor. Victims saw fake Adobe Flash or Adobe installer downloads during a compromised webmail visit.
Antino then used Microsoft Graph API traffic for command and control, while the extension supplied a view into online activity.
Jewelbug also used ClientKing, a Linux and router implant capable of reaching servers and network equipment. That gave the operation a way to expand beyond a browser foothold and into the surrounding environment.
Watering Holes Put Government Networks at Risk
Jewelbug’s largest campaign targeted a shared government webmail platform in the Middle East.
Rather than attack each ministry separately, the group added a script to a hosting environment. Visitors to affected login and mailbox pages could then be connected to attacker-controlled infrastructure.
A lure document impersonating the CSIS Indo-Pacific Forecast 2026 event page (Source – Symantec)
This approach, known as a watering-hole attack, is effective because people encounter the trap while using a trusted service.
Similar government watering hole incidents show how a compromised public site can expose high-value users without relying on a suspicious email.
The script collected cookies and identified users through government email addresses. It then displayed a fake update prompt only to selected Windows users in targeted domains.
On one system, operators captured authenticated traffic to a virtualisation-management service, evidence that browser theft had become a bridge into internal infrastructure.
Jewelbug also ran a fraud operation that used fake cryptocurrency exchange download pages and search-result manipulation to attract Chinese-speaking victims.
The overlap matters because shared infrastructure can allow a money-making scheme to support espionage, much like APT operations targeting governments that use several access methods.
Defenders should review browser extensions, remove unknown add-ons, investigate native-messaging registrations, and watch for fake software-update prompts.
Agencies should check webmail templates for unauthorized scripts, rotate exposed sessions and credentials, segment administration systems, and monitor unusual requests to internal services.
Prompt patching and review of third-party hosting access can reduce the chance that one compromised platform becomes an exposure.
Indicators of Compromise (IoCs):-
Type Indicator Description
SHA-256 e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf HTA lure document
SHA-256 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a HTA downloader, Russia/Venezuela/Ukraine lure
SHA-256 e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 HTA lure document
SHA-256 f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 TEST.hta
SHA-256 e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 slc.dll
SHA-256 e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb Vb0c44dfslc.dll.wx
SHA-256 b09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff Antino backdoor
SHA-256 c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc Antino backdoor
SHA-256 b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e flashcenter_pp_ax_install_en.exe
SHA-256 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd Antino sample connecting to Microsoft Graph API
SHA-256 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 Adobe_installer (1).exe
SHA-256 153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e Antino-related sample on infected Middle Eastern host
SHA-256 297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561 Antino-related sample on infected Middle Eastern host
SHA-256 30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d Antino-related sample on infected Middle Eastern host
SHA-256 430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55 Antino-related sample on infected Middle Eastern host
SHA-256 5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef Antino-related sample on infected Middle Eastern host
SHA-256 5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac Antino-related sample on infected Middle Eastern host
SHA-256 6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2 Antino-related sample on infected Middle Eastern host
SHA-256 97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad Antino-related sample on infected Middle Eastern host
SHA-256 ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813 Antino-related sample on infected Middle Eastern host
SHA-256 e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0 Antino-related sample on infected Middle Eastern host
SHA-256 ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877 Antino-related sample on infected Middle Eastern host
SHA-256 ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869 Antino-related sample on infected Middle Eastern host
Domain fonts[.]tarotfree101[.]top Command-and-control infrastructure
Domain fonts[.]chrorne[.]com Typosquatted payload-hosting domain
Domain robot[.]avbliud[.]com Command-and-control infrastructure
Domain microsoft-flash[.]com Malicious download infrastructure
Domain www[.]wps-cn[.]com Command-and-control infrastructure
Domain www[.]f1ash[.]org[.]cn Malicious download infrastructure
Domain browser-update[.]pages[.]dev Command-and-control infrastructure
Domain eastus2[.]wac-azure[.]com Command-and-control infrastructure
Domain mailbycloud[.]com Command-and-control infrastructure
Domain www[.]jkskhei[.]com Command-and-control infrastructure
Domain ns1[.]jkskhei[.]com Command-and-control infrastructure
Domain dns[.]wizkidblogger[.]com Command-and-control infrastructure
Domain r6fi2yvqql[.]execute-api[.]ap-southeast-2[.]amazonaws[.]com Command-and-control infrastructure
IP address 103[.]87[.]9[.]62 Network indicator
IP address 152[.]42[.]174[.]15 Network indicator
IP address 143[.]246[.]208[.]236 Network indicator
IP address 43[.]246[.]208[.]179 Network indicator
IP address 47[.]84[.]37[.]113 Network indicator
IP address 47[.]84[.]51[.]173 Network indicator
IP address 167[.]71[.]195[.]255 Network indicator
IP address 38[.]12[.]1[.]47 Network indicator
IP address 129[.]212[.]237[.]224 Network indicator
IP address 47[.]87[.]71[.]167 Network indicator
IP address 47[.]250[.]208[.]35 Network indicator
IP address 219[.]76[.]254[.]184 Network indicator
URL hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA.log Payload or log-delivery URL
URL hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc.dll.iwq Malicious DLL URL
URL hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe Antino download URL
URL hxxps://www[.]f1ash[.]org[.]cn/flashcenter_pp_ax_install_cn.exe Malicious download URL
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks
Cyber Security
Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
Cyber Security News
North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees
Cyber Security News
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
Cyber Security News
GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?