A Chinese hacking group, Jewellburg, has been found to operate cyber espionage activities targeting government and military institutions alongside cryptocurrency fraud using the same infrastructure. Symantec reported that Jewellburg conducted both operations simultaneously through a single control panel called XG-Web. According to the report, over 1 million implant check-ins and more than 580,000 browser cookie thefts were confirmed between February and May 2026. Jewellburg created fake exchange download pages to target Chinese-speaking users and manipulated search rankings to increase traffic. Attackers displayed pages that appeared to be legitimate exchanges while hiding phishing content to lure users. The browser extension 'PDF Viewer' had the capability to steal cookies and login information. Symantec stated that Jewellburg operated a Windows backdoor called Antinodo and used legitimate cloud services as command and control channels to make detection difficult. This report illustrates that user terminals and search paths can be exploited as attack surfaces, rather than just the exchange itself.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.



























![[Editorial] The Rails Are Laid Before the World Notices](/public-static/8_1497610e7c.png?format=avif)

