Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Jewelbug Exploits Browsers to Infiltrate Government Systems

Jewelbug Exploits Browsers to Infiltrate Government Systems

Posted on August 13, 2026 By CWS

Jewelbug, a sophisticated cyber threat group based in China, has transformed ordinary web browsing into a strategic tool for espionage. By targeting government webmail systems, they have managed to steal browser cookies, thereby gaining a window into the activities within compromised networks. This operation has affected numerous ministries and targets across regions including the Middle East, Southeast Asia, and South Asia.

Widespread Government System Breaches

In a significant breach, Jewelbug inserted a malicious script into over 15 government webmail platforms, enabling access to officials’ accounts. Symantec analysts have identified Jewelbug as a hackers-for-hire group that merges espionage activities with cryptocurrency fraud. Their report to Cyber Security News highlights the use of a unified team, infrastructure, and control panel to support these dual objectives, blurring the lines between intelligence gathering and profit-driven cybercrime.

The scale of Jewelbug’s operations is alarming. Investigations reveal over one million implant check-ins, 580,000 stolen browser cookies, thousands of captured credentials, and more than 2,300 stolen email contents. Such extensive access can expose sensitive information and facilitate deeper network infiltration.

Browser Hijacking Techniques

Central to Jewelbug’s strategy is the XG-Web system, a browser-focused control panel that remotely manages compromised browsers. Their main tool is a malicious extension disguised as a ‘PDF Viewer’ for Chrome and Firefox, which seeks permissions far beyond those required for a document reader. Once installed, this extension can read cookies, capture session tokens, inspect browsing activity, and even take screenshots and clipboard content.

The extension also injects malicious code into websites, intercepts browser traffic, and communicates with a Windows helper component masquerading as a legitimate Edge function to execute commands on infected devices. This underscores the significant threat posed by malicious browser extensions as an entry point for account theft.

Expanding the Scope of Attacks

Jewelbug extends its reach beyond browsers using the Antino backdoor, which is deployed during visits to compromised webmail sites via fake Adobe Flash or installer downloads. Antino utilizes Microsoft Graph API for command and control, providing a comprehensive view of online activity. Additionally, the group employs ClientKing, a Linux and router implant that can infiltrate servers and network equipment, broadening their operational reach.

In one notable campaign, Jewelbug targeted a shared government webmail platform in the Middle East using a watering-hole attack. By embedding a script in the hosting environment, the group redirected users of the affected service to their infrastructure, gathering cookies and user identifications through government email addresses. This method effectively compromises high-value targets without relying on suspicious emails.

Security Measures and Recommendations

Jewelbug’s operations also encompass fraudulent activities such as fake cryptocurrency exchange downloads, which lure Chinese-speaking users. The dual use of infrastructure for espionage and fraud highlights the complexity of their operations. To combat such threats, defenders should rigorously audit browser extensions, remove unknown add-ons, and scrutinize native-messaging registrations. Monitoring for unauthorized scripts in webmail templates, rotating exposed sessions and credentials, and segmenting administrative systems are essential steps to mitigate risks.

Consistent patching and reviewing third-party hosting access can help prevent a compromised platform from leading to broader exposure. By staying vigilant and proactive, organizations can better protect themselves against sophisticated threats like those posed by Jewelbug.

Cyber Security News Tags:APT, browser hijacking, cyber attack, cyber threat, Cybersecurity, government espionage, government networks, Jewelbug, Malware, webmail compromise

Post navigation

Previous Post: North Korean IT Workers Exploit AI and Remote Access
Next Post: Armored Likho Tool Compromises Telegram & Records Conversations

Related Posts

Microsoft’s Record M Bug Bounty Payout Microsoft’s Record $20M Bug Bounty Payout Cyber Security News
Microsoft Office Vulnerabilities Let Attackers Execute Remote Code Microsoft Office Vulnerabilities Let Attackers Execute Remote Code Cyber Security News
Critical Flaw in Apache Server Prompts Urgent Security Update Critical Flaw in Apache Server Prompts Urgent Security Update Cyber Security News
Firefox 140 Released With Fix for Code Execution Vulnerability Firefox 140 Released With Fix for Code Execution Vulnerability Cyber Security News
Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials Cyber Security News
New Clickfix Attack Promises “Free WiFi” But Delivers Powershell Based Malware New Clickfix Attack Promises “Free WiFi” But Delivers Powershell Based Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems
  • North Korean IT Workers Exploit AI and Remote Access
  • Data Breach at ShipMonk Risks Trezor Customer Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems
  • North Korean IT Workers Exploit AI and Remote Access
  • Data Breach at ShipMonk Risks Trezor Customer Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark