Broadcom said on August 13 that Jewelbug, also tracked as Ink Dragon, Earth Alux, REF770, and CL-STA-0049, is running state-linked espionage and profitable crypto fraud from the same small team, shared infrastructure, and one control panel. The group has used that setup against governments and militaries while also targeting Chinese-speaking cryptocurrency users.
The operators blend command-and-control into ordinary cloud-service traffic, including services such as Google Docs and other trusted online platforms, so the traffic looks like normal use instead of custom malware beaconing. That makes the espionage and the fraud part of one machine, which complicates both attribution and blocking because cutting off one track does not necessarily disrupt the other.
For defenders, the important map point is that cloud-app traffic is not automatically low-risk when the same infrastructure can carry both espionage and monetization. In shops that already allow those services, the trust boundary is the service itself, not just the endpoint or the malware sample.