Jewelbug — APT Profile
Jewelbug is a China-nexus cyberespionage group named by Symantec (Broadcom), active since at least mid-2023, that has targeted government and corporate networks in South America, South and Southeast Asia, and Taiwan. In 2025 the group carried out a roughly five-month intrusion (January-May) into a Russian IT service provider, gaining access to code-repository and software build systems in what researchers assessed as a possible attempted software supply-chain attack, and exfiltrating data via the legitimate Yandex Cloud service to blend in with normal traffic. A hallmark of the group is its use of a renamed Microsoft Console Debugger (cdb.exe) to run shellcode, bypass application allowlisting and terminate security tools. In a separate October-November 2024 intrusion at a Taiwanese software company the group used DLL side-loading to deploy the ShadowPad modular backdoor alongside BYOVD abuse of a vulnerable anti-cheat driver.Also tracked as
Earth Alux, REF7707, CL-STA-0049
IntelFusions coverage (1)
- One control panel ran Chinese spying and crypto fraud 2026-08-16 · Nation-State
Vendor research
- full report Symantec (Broadcom) Threat Hunter Team
Countries linked to this actor
- Russia targets