CYBERSECURITYTRACKER
TRACKING
Permanent story citation

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4522

As cited

Copy frozen at (site build).

threat intel

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

Jewelbug, a China-linked threat actor, operates a dual mission of government and military espionage alongside cryptocurrency fraud, coordinating both activities through XG-Web, a browser-based remote access and information-stealing framework that enables full remote control of compromised systems.

Why it matters: Government, military, and cryptocurrency ecosystem organizations should assess exposure to Jewelbug campaigns and evaluate browser security controls, as the group leverages a single infrastructure for both espionage and financial theft targeting high-value targets.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary