cognitive cybersecurity intelligence

News and Analysis

Search

Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks

Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks

Jewelbug has turned ordinary web browsing into an entry point for espionage. The China-based group compromised government webmail systems, stole browser cookies, and used that access to watch activity inside affected networks.

Its campaigns reached ministries and targets across the Middle East, Southeast Asia, and South Asia.

In one major incident, a malicious script was placed across more than 15 government webmail tenants, giving attackers a path to officials’ accounts.

Analysts from Symantec identified Jewelbug as a hackers-for-hire operation that combines government spying with cryptocurrency fraud.

Symantec said in a report shared with Cyber Security News (CSN) that the same team, infrastructure, and control panel supported both missions, blurring targeted intelligence collection and profit-driven crime.

Control panel (Source – Symantec)

The scale is striking. Investigators found more than one million implant check-ins, over 580,000 stolen browser cookies, thousands of captured credentials, and more than 2,300 stolen email bodies.

Such access can expose sensitive correspondence and help attackers move deeper into a network.

Jewelbug APT Hijacks Browsers

At the centre of the activity is XG-Web, a browser-focused control system that lets operators remotely direct an infected browser.

Its main lure was a malicious Chrome and Firefox extension called “PDF Viewer,” presented as a document reader while requesting access far beyond what such an extension needs.

Once installed, the extension could read cookies, watch for new session tokens, inspect browsing history and bookmarks, take screenshots, and capture clipboard contents.

The XG-Web operator panel (Source – Symantec)

Stolen cookies can let criminals reuse a logged-in session, which is why browser cookie theft risks remain serious even where an account uses multi-factor authentication.

The extension also injected code into websites and intercepted browser traffic. It communicated with a Windows helper called com.microsoft.runedge, masquerading as an Edge component, to run commands on the device.

This reflects the wider danger of malicious browser extension campaigns, where a small add-on can become a route to account theft.

The group paired this browser access with its Antino backdoor. Victims saw fake Adobe Flash or Adobe installer downloads during a compromised webmail visit.

Antino then used Microsoft Graph API traffic for command and control, while the extension supplied a view into online activity.

Jewelbug also used ClientKing, a Linux and router implant capable of reaching servers and network equipment. That gave the operation a way to expand beyond a browser foothold and into the surrounding environment.

Watering Holes Put Government Networks at Risk

Jewelbug’s largest campaign targeted a shared government webmail platform in the Middle East.

Rather than attack each ministry separately, the group added a script to a hosting environment. Visitors to affected login and mailbox pages could then be connected to attacker-controlled infrastructure.

A lure document impersonating the CSIS Indo-Pacific Forecast 2026 event page (Source – Symantec)

This approach, known as a watering-hole attack, is effective because people encounter the trap while using a trusted service.

Similar government watering hole incidents show how a compromised public site can expose high-value users without relying on a suspicious email.

The script collected cookies and identified users through government email addresses. It then displayed a fake update prompt only to selected Windows users in targeted domains.

On one system, operators captured authenticated traffic to a virtualisation-management service, evidence that browser theft had become a bridge into internal infrastructure.

Jewelbug also ran a fraud operation that used fake cryptocurrency exchange download pages and search-result manipulation to attract Chinese-speaking victims.

The overlap matters because shared infrastructure can allow a money-making scheme to support espionage, much like APT operations targeting governments that use several access methods.

Defenders should review browser extensions, remove unknown add-ons, investigate native-messaging registrations, and watch for fake software-update prompts.

Agencies should check webmail templates for unauthorized scripts, rotate exposed sessions and credentials, segment administration systems, and monitor unusual requests to internal services.

Prompt patching and review of third-party hosting access can reduce the chance that one compromised platform becomes an exposure.

Indicators of Compromise (IoCs):-

TypeIndicatorDescriptionSHA-256e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcfHTA lure documentSHA-25601b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31aHTA downloader, Russia/Venezuela/Ukraine lureSHA-256e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34HTA lure documentSHA-256f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8TEST.htaSHA-256e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530slc.dllSHA-256e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bbVb0c44dfslc.dll.wxSHA-256b09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cffAntino backdoorSHA-256c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42ccAntino backdoorSHA-256b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85eflashcenter_pp_ax_install_en.exeSHA-2560c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bdAntino sample connecting to Microsoft Graph APISHA-2569b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3Adobe_installer (1).exeSHA-256153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94eAntino-related sample on infected Middle Eastern hostSHA-256297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561Antino-related sample on infected Middle Eastern hostSHA-25630f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61dAntino-related sample on infected Middle Eastern hostSHA-256430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55Antino-related sample on infected Middle Eastern hostSHA-2565ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97efAntino-related sample on infected Middle Eastern hostSHA-2565edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7acAntino-related sample on infected Middle Eastern hostSHA-2566d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2Antino-related sample on infected Middle Eastern hostSHA-25697c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aadAntino-related sample on infected Middle Eastern hostSHA-256ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813Antino-related sample on infected Middle Eastern hostSHA-256e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0Antino-related sample on infected Middle Eastern hostSHA-256ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877Antino-related sample on infected Middle Eastern hostSHA-256ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869Antino-related sample on infected Middle Eastern hostDomainfonts[.]tarotfree101[.]topCommand-and-control infrastructureDomainfonts[.]chrorne[.]comTyposquatted payload-hosting domainDomainrobot[.]avbliud[.]comCommand-and-control infrastructureDomainmicrosoft-flash[.]comMalicious download infrastructureDomainwww[.]wps-cn[.]comCommand-and-control infrastructureDomainwww[.]f1ash[.]org[.]cnMalicious download infrastructureDomainbrowser-update[.]pages[.]devCommand-and-control infrastructureDomaineastus2[.]wac-azure[.]comCommand-and-control infrastructureDomainmailbycloud[.]comCommand-and-control infrastructureDomainwww[.]jkskhei[.]comCommand-and-control infrastructureDomainns1[.]jkskhei[.]comCommand-and-control infrastructureDomaindns[.]wizkidblogger[.]comCommand-and-control infrastructureDomainr6fi2yvqql[.]execute-api[.]ap-southeast-2[.]amazonaws[.]comCommand-and-control infrastructureIP address103[.]87[.]9[.]62Network indicatorIP address152[.]42[.]174[.]15Network indicatorIP address143[.]246[.]208[.]236Network indicatorIP address43[.]246[.]208[.]179Network indicatorIP address47[.]84[.]37[.]113Network indicatorIP address47[.]84[.]51[.]173Network indicatorIP address167[.]71[.]195[.]255Network indicatorIP address38[.]12[.]1[.]47Network indicatorIP address129[.]212[.]237[.]224Network indicatorIP address47[.]87[.]71[.]167Network indicatorIP address47[.]250[.]208[.]35Network indicatorIP address219[.]76[.]254[.]184Network indicatorURLhxxp://d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA.logPayload or log-delivery URLURLhxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc.dll.iwqMalicious DLL URLURLhxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exeAntino download URLURLhxxps://www[.]f1ash[.]org[.]cn/flashcenter_pp_ax_install_cn.exeMalicious download URL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts