Update Flash — and lose your computer: The old hacker trick is still working

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
362
Reaction score
596
Deposit
0$
The Chinese group Jewelbug has turned the same infrastructure into a tool for two tasks at once: to monitor government organizations and earn money on cryptocurrency fraud. Symantec specialists found that both operations were managed by a small team through a common system, and the base it collected contained traces of thousands of infected devices.





Jewelbug, also known as Earth Alux, REF7707 and CL-STA-0049, attacked state and military organizations in the Middle East, Southeast and South Asia. In separate lists of targets, specialists found more than 90 e-mail addresses of the police and government agencies. In parallel, the attackers lured the Chinese-speaking owners of cryptocurrencies to fake sites of exchanges.





The infrastructure center was the XG-Web platform. The malicious “PDF Viewer” extension for Chrome and Firefox accessed cookies, history, bookmarks, clipboard, and network requests. Operators could execute scripts on open pages and intercept credentials. The code also included a function that replaced the copied address of the cryptocurrency wallet, although it was not used during the attacks studied.





To go beyond the browser, Jewelbug used an auxiliary program under Windows, disguised as a Microsoft Edge component. It allowed to execute commands in the system. Another tool was the Antino backdoor, which was distributed under the guise of Adobe installers and associated with the control infrastructure through Microsoft Graph. For servers and network equipment, the group has prepared 37 variants of the ClientKing malware on Rust.

The scale of the operations was unusually large. In the incomplete three months, the Jewelbug database was approached more than 1 million times, and the intruders stole more than 580 thousand cookies. They also collected several thousand credentials and more than 2300 texts of e-mails. The magazines contained about 1.1 million location records of approximately 4,300 unique IP addresses.





In one of the largest operations, Jewelbug gained access to a common public webmail platform in a Middle Eastern country. Instead of attacking each agency separately, the attackers added a malicious scenario to the overall service template. As a result, the code simultaneously appeared in more than 15 state postal systems. After the employee logged in, the script stole cookies, and the fake window, which offered to update Adobe Flash, helped to install Antino.





In parallel, the team developed a commercial scheme with fake sites of cryptocurrency exchanges. The system automatically created thousands of pages similar to OKX and Binance sites, and more than 40 servers and special programs helped to promote them in the search results. Symantec linked the commercial part of the infrastructure to a registered company in the Chinese province of Hunan. According to experts, Jewelbug is more like a hacker team working on a commissioned team that combines cyber espionage with its own criminal business.
 
Top Bottom