Jewelbug, a sophisticated cyber threat group based in China, has transformed ordinary web browsing into a strategic tool for espionage. By targeting government webmail systems, they have managed to steal browser cookies, thereby gaining a window into the activities within compromised networks. This operation has affected numerous ministries and targets across regions including the Middle East, Southeast Asia, and South Asia.
Widespread Government System Breaches
In a significant breach, Jewelbug inserted a malicious script into over 15 government webmail platforms, enabling access to officials’ accounts. Symantec analysts have identified Jewelbug as a hackers-for-hire group that merges espionage activities with cryptocurrency fraud. Their report to Cyber Security News highlights the use of a unified team, infrastructure, and control panel to support these dual objectives, blurring the lines between intelligence gathering and profit-driven cybercrime.
The scale of Jewelbug’s operations is alarming. Investigations reveal over one million implant check-ins, 580,000 stolen browser cookies, thousands of captured credentials, and more than 2,300 stolen email contents. Such extensive access can expose sensitive information and facilitate deeper network infiltration.
Browser Hijacking Techniques
Central to Jewelbug’s strategy is the XG-Web system, a browser-focused control panel that remotely manages compromised browsers. Their main tool is a malicious extension disguised as a ‘PDF Viewer’ for Chrome and Firefox, which seeks permissions far beyond those required for a document reader. Once installed, this extension can read cookies, capture session tokens, inspect browsing activity, and even take screenshots and clipboard content.
The extension also injects malicious code into websites, intercepts browser traffic, and communicates with a Windows helper component masquerading as a legitimate Edge function to execute commands on infected devices. This underscores the significant threat posed by malicious browser extensions as an entry point for account theft.
Expanding the Scope of Attacks
Jewelbug extends its reach beyond browsers using the Antino backdoor, which is deployed during visits to compromised webmail sites via fake Adobe Flash or installer downloads. Antino utilizes Microsoft Graph API for command and control, providing a comprehensive view of online activity. Additionally, the group employs ClientKing, a Linux and router implant that can infiltrate servers and network equipment, broadening their operational reach.
In one notable campaign, Jewelbug targeted a shared government webmail platform in the Middle East using a watering-hole attack. By embedding a script in the hosting environment, the group redirected users of the affected service to their infrastructure, gathering cookies and user identifications through government email addresses. This method effectively compromises high-value targets without relying on suspicious emails.
Security Measures and Recommendations
Jewelbug’s operations also encompass fraudulent activities such as fake cryptocurrency exchange downloads, which lure Chinese-speaking users. The dual use of infrastructure for espionage and fraud highlights the complexity of their operations. To combat such threats, defenders should rigorously audit browser extensions, remove unknown add-ons, and scrutinize native-messaging registrations. Monitoring for unauthorized scripts in webmail templates, rotating exposed sessions and credentials, and segmenting administrative systems are essential steps to mitigate risks.
Consistent patching and reviewing third-party hosting access can help prevent a compromised platform from leading to broader exposure. By staying vigilant and proactive, organizations can better protect themselves against sophisticated threats like those posed by Jewelbug.
