Skip to content
Tech News
← Back to articles

Hackers breach govt webmail while running parallel crypto fraud

read original more articles
Why This Matters

The Jewelbug hacker group's dual operations of espionage and cryptocurrency fraud highlight the growing sophistication and multifaceted nature of cyber threats targeting government and critical infrastructure. This underscores the urgent need for improved cybersecurity measures to protect sensitive data and financial assets in an increasingly interconnected digital landscape.

Key Takeaways

The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud.

Although the threat actor has targeted government agencies and organizations in critical sectors, including defense, telecommunications, education, and aviation, its cryptocurrency-related activity suggests that they may also operate as a hack-for-hire group that seeks to profit from cybercrime.

In a recent operation, Jewelbug (also known as Earth Alux and REF7707) compromised webmail accounts belonging to 15 government tenants as part of a campaign targeting a country in the Middle East.

Researchers at Symantec found that the espionage campaign and the cryptocurrency fraud were conducted from the same control panel.

The China-based hacker group gained write access to the shared webmail installation and inserted a malicious script into its common template. The script then ran on login pages and mailbox views across 15 tenants.

The webmail attack chain

Source: Symantec

After execution, the script established a WebSocket connection to the attacker's command-and-control (C2) server, exfiltrated webmail cookies, and retrieved the user's email address to determine whether it belonged to a targeted government domain.

Valuable targets would receive a fake Adobe Flash update prompt, which installs the main payload on Windows, the Antino backdoor, and browser tooling.

Apart from Antino, the threat actor also uses the XG-Web remote-access and data-theft framework for managing campaigns and victim information.

... continue reading