Jewelbug — APT Profile

Jewelbug is a China-nexus cyberespionage group named by Symantec (Broadcom), active since at least mid-2023, that has targeted government and corporate networks in South America, South and Southeast Asia, and Taiwan. In 2025 the group carried out a roughly five-month intrusion (January-May) into a Russian IT service provider, gaining access to code-repository and software build systems in what researchers assessed as a possible attempted software supply-chain attack, and exfiltrating data via the legitimate Yandex Cloud service to blend in with normal traffic. A hallmark of the group is its use of a renamed Microsoft Console Debugger (cdb.exe) to run shellcode, bypass application allowlisting and terminate security tools. In a separate October-November 2024 intrusion at a Taiwanese software company the group used DLL side-loading to deploy the ShadowPad modular backdoor alongside BYOVD abuse of a vulnerable anti-cheat driver.

Also tracked as

Earth Alux, REF7707, CL-STA-0049

IntelFusions coverage (1)

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions