One control panel ran Chinese spying and crypto fraud

The same control panel that ran a Chinese state espionage operation was also running a for-profit cryptocurrency scam business. Symantec's Threat Hunter Team, which published the finding on 13 August, found both missions administered from a single browser-centric platform called XG-Web, backed by one database holding more than a million implant check-ins.

Diagram showing the XG-Web control panel feeding two operations, espionage against governments and cryptocurrency fraud against exchange users, with shared harvest figures below.

Jewelbug's two operations ran from one panel. Diagram by IntelFusions.

The group is tracked as Jewelbug, also known as Earth Alux, REF7707 and CL-STA-0049. Symantec assesses with high confidence that it works for China, most likely for a state intelligence client. It is the second Chinese operation to surface this month alongside a spy backdoor that hides itself inside Windows.

Two jobs, one login

XG-Web is a React panel over a Node.js backend and a MySQL database. Its own internal documentation describes its functions as browser hijacking, data theft and man-in-the-middle attack. The database Symantec examined held more than 580,000 stolen browser cookies, several thousand captured credentials and over 2,300 exfiltrated email bodies, plus roughly 1.1 million geolocation events against about 4,300 distinct IP addresses.

The espionage side reached government ministries across the Middle East, South Asia and Southeast Asia, state telecommunications providers, national network-services agencies and military infrastructure. In a single operation the group compromised more than 15 government webmail tenants by inserting one script into a shared telecom webmail host, and Symantec counted over 90 police and government email addresses in South Asia. A major US aerospace and industrial manufacturer appears in the data as proxy infrastructure.

A scam factory built by AI

The fraud side went after Chinese-speaking cryptocurrency users through fake exchange-download portals. Symantec says the operators used an artificial-intelligence article generator to produce thousands of fake download pages, and registered hundreds of look-alike domains impersonating the OKX and Binance exchanges. The pages were cloaked, so crawlers saw phishing content while ordinary visitors were redirected.

Who was actually doing what

This is where Symantec is careful, and the hedge is worth repeating rather than flattening. Instead of concluding that one person held both jobs, the team writes that it assesses it most likely that the SEO business supplied access, infrastructure and delivery to the espionage operation. That describes a supplier relationship, not a moonlighting spy, and it echoes what happens when a China-nexus crew leaves its own attack server open: the plumbing tells you more about the arrangement than the malware does.

The swap that never fired

One detail cuts against the obvious headline. The toolkit includes a clipboard module able to silently swap a copied cryptocurrency address for the attacker's own, but Symantec found no address-replacement rules deployed. The module was live on victims and the feature simply was not used during the observed period. The capability was present. The theft, on the evidence published, was not.

Where to look on your network

Three implants carry the operation. Antino is a Windows backdoor that uses the Microsoft Graph API for command and control and arrives inside fake Adobe Flash and installer executables. A malicious Chrome and Firefox extension posing as a PDF viewer requests cookie, scripting, debugger, web-request and download permissions, and registers a native helper under the name com.microsoft.runedge that hands the operator a command shell. ClientKing is a Rust implant for Linux and routers, seen in 37 builds, supporting DNS tunnelling, SOCKS pivoting and kernel module loading. Hunt for outbound Graph API traffic from hosts with no Microsoft 365 role, and audit browser extensions for native messaging hosts impersonating Microsoft names. Symantec's full report carries the indicator set, among them the domains fonts[.]chrorne[.]com, microsoft-flash[.]com and mailbycloud[.]com, and the addresses 103[.]87[.]9[.]62, 152[.]42[.]174[.]151 and 43[.]246[.]208[.]236.

What makes Jewelbug awkward is not any single tool. It is that one login, one set of servers and one database served a nation's intelligence requirements and a scam aimed at retail crypto buyers at the same time. Attribution work that assumes those are separate worlds will keep drawing the boundary in the wrong place.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions