# Jewelbug crypto fraud exposed: 580,000 stolen cookies behind fake exchanges

> Source: <https://cryptonews.net/news/security/33292902/>
> Published: 2026-08-13 20:49:00+00:00

A hacking crew that spends its days spying on governments and its nights running fake crypto exchanges sounds like something out of a heist movie. But according to new research from Broadcom’s Symantec Threat Hunter Team, that is exactly the profile of Jewelbug, a China-based hacker-for-hire group now drawing attention for blending state-linked espionage with large-scale **Jewelbug crypto fraud** operations aimed squarely at everyday cryptocurrency users.

## Key takeaways

- Jewelbug is a China-based hacker-for-hire group running parallel espionage and cryptocurrency fraud campaigns from a single command-and-control panel.
- Its crypto scheme relies on AI-generated fake exchange pages and hundreds of lookalike domains impersonating Binance and OKX.
- Symantec found the group also compromised government, military and telecommunications targets across Asia and the Middle East, plus a major US industrial and aerospace manufacturer.
- Researchers uncovered more than 580,000 stolen browser cookie sets and 2,300 exfiltrated email bodies tied to Jewelbug’s operations.
- Symantec’s Dick O’Brien says the scale of the fraud business suggests this is far more than a side hustle for a state-linked actor.

## Jewelbug’s Dual Cyber Operations

Jewelbug operates as a mercenary outfit that appears equally comfortable stealing state secrets as it is draining crypto wallets. Symantec’s researchers describe a group that switches between government espionage and cryptocurrency fraud “with the same ease as jumping between browser tabs,” managing both lines of work from one custom-built control panel.

### Government Espionage Activities

On the espionage side, Jewelbug has compromised government, military and telecommunications organizations across Asia and the Middle East. Its most notable operation targeted a Middle Eastern government by breaching a shared web hosting platform run by the country’s state-owned telecom and network services provider, rather than attacking individual agencies one by one. Once inside, the attackers planted a script on the webmail platform that quietly enrolled government staff into their tracking system, [stole login cookies](https://www.dni.gov/files/NCSC/documents/news/20180724-economic-espionage-pub.pdf), and served fake Adobe Flash update prompts hiding malware.

Other campaigns hit navy, police and army intelligence bodies in Southeast Asia, alongside a major US industrial and aerospace manufacturer. By Symantec’s count, the group amassed more than 580,000 full browser cookie sets, roughly 2,300 fully exfiltrated email bodies, and several thousand stolen login credentials, spanning thousands of distinct victims.

Dick O’Brien, principal intelligence analyst for the Symantec Threat Hunter Team, said the pattern points strongly toward China, though he stopped short of drawing a direct line. “Given their location and their targeting, by far the most likely scenario is that they are working for China,” he said, adding that spying on behalf of another government would be “a very risky proposition” for a group like Jewelbug.

### Cryptocurrency Fraud Scheme

When it isn’t spying on foreign governments, Jewelbug turns its infrastructure toward ordinary crypto users. Symantec found the group ran a financial fraud business of striking scale, one that O’Brien says is the biggest clue this isn’t a side project. “The sheer scale of the fraud business is the biggest clue,” he said. “They aren’t just making a little extra money by moonlighting.”

## Cryptocurrency Fraud Techniques and Targets

Jewelbug’s crypto operation leans heavily on automation and artificial intelligence to build convincing fake trading sites at scale, then drives traffic to them through manipulated search rankings.

### AI-Generated Fake Exchange Pages

The group uses AI tools to generate thousands of phishing pages themed around cryptocurrency, sports betting and other topics, all managed through a fleet of 44 content management servers, according to Symantec. To push these fake pages higher in search results, Jewelbug deploys click-fraud bots and filters out web crawlers with a PHP script, so automated scanners see harmless content while real visitors get funneled toward the malicious pages and, eventually, malware.

One of the group’s more unusual tools is a browser extension disguised as a “PDF Viewer.” Rather than opening documents, it requests sweeping permissions and harvests cookies, session tokens, browsing history and screenshots. It also lets attackers escape the browser sandbox, inject code into any webpage, and even swap a victim’s crypto wallet address for the attacker’s own during a transaction, a feature Symantec says hasn’t been observed in active use yet.

### Impersonation of Binance and OKX via Lookalike Domains

The clearest evidence of the group’s ambitions in **China hacker espionage**-adjacent financial crime is its impersonation campaign against two of the industry’s biggest names. Jewelbug has registered hundreds of lookalike domains built to mimic Binance and OKX, two of the world’s largest cryptocurrency exchanges, in an effort to trick users into handing over credentials or funds through what look like **Binance fake exchange sites**.

Both exchanges were named specifically as targets in the impersonation scheme, underscoring how attackers increasingly go after the platforms crypto users already trust rather than building fraud from scratch. This kind of brand impersonation matters because it exploits familiarity: users searching for a legitimate exchange login page can land on a near-identical fake without realizing it, especially when those pages rank well in search results thanks to manipulated traffic.

## Symantec Threat Hunter Report Findings

All of these findings trace back to the **Symantec Threat Hunter report**, which pieced together Jewelbug’s infrastructure through a management platform called “XG-Web.” The platform functions much like commercial software-as-a-service tools, letting operators generate malicious code, manage stolen browser data and oversee individual infections from a single dashboard.

XG-Web’s design also reveals something about the group’s internal structure. It uses role-based access controls with superadmin, admin and ordinary user tiers, and lower-level operators can only see the victims they personally infected. Based on this setup, Symantec characterizes Jewelbug as a relatively small team rather than a sprawling operation.

Researchers also point to a broader trend behind groups like Jewelbug. O’Brien noted that reliance on third-party contractors has grown among nation-states, with China representing “the main growth area,” largely because of the scale at which it wants to operate in cyberspace. That outsourcing model can complicate attribution for defenders, he said, since contracted groups often show “quite an inconsistent pattern of activity.” It can also offer states a layer of plausible deniability, though it comes with tradeoffs. “You have less oversight over operations,” O’Brien said, noting that financially motivated hackers tend to have weaker operational security, “as evidenced by Jewelbug, who left a trail of evidence behind them.”

That trail is precisely what let Symantec map the group’s tools, infrastructure and victims in such detail, and it’s a reminder that even sophisticated dual-purpose operations can unravel once researchers start pulling on the right thread.

## FAQ

### Who is Jewelbug?

Jewelbug is a China-based hacker-for-hire group conducting cyber espionage and cryptocurrency fraud.

### What types of operations does Jewelbug run?

Jewelbug simultaneously conducts government espionage and cryptocurrency fraud operations, managing both from a single custom command-and-control panel.

### How does Jewelbug carry out its cryptocurrency fraud?

The group uses AI-generated fake exchange pages and hundreds of lookalike domains impersonating Binance and OKX, boosting their visibility with click-fraud bots and search manipulation.

### Which cryptocurrency exchanges were targeted by Jewelbug’s fraud attempts?

Binance and OKX were specifically targeted through impersonation with fake domains designed to look like their legitimate platforms.

*Article produced with the assistance of artificial intelligence and reviewed by the editorial team.*
