Jewelbug Merges Espionage and Crypto Theft

Symantec identified Jewelbug, a China-linked mercenary APT, using one browser-based command-and-control panel to run both state-style espionage and opportunistic cryptocurrency theft. The same operator set is also behind fake crypto-exchange fraud, which makes the campaign look like ordinary cybercrime and intelligence work at the same time. Its browser extension, PDF Viewer, asks for broad permissions and can steal cookies, session tokens, history, screenshots, and traffic, then control the victim’s browser like a remote user. That means a browser session can be the prize, not just a password, and the same infrastructure can support spying, fraud, or both without changing the core setup. For defenders, the map changes: a single intrusion may belong to a wider dual-use campaign, and the forensic trail may look like crime even when the objective is espionage. If your environment includes government, telecom, or crypto-facing users, shared C2 and browser-session theft are part of the same threat picture.

Part of the PlainSec briefing for 2026-08-14

Editions

Sources