What happened
Symantec published its Jewelbug investigation on August 13, 2026 after gaining visibility into the group’s control panel, database, server logs, source code and operator files. The researchers describe Jewelbug, also tracked as Earth Alux and REF7707, as operating espionage and cryptocurrency-fraud campaigns through the XG-Web browser-centric remote-access and information-stealing platform. One planted script placed a watering hole on more than 15 government webmail tenants using a shared platform. The script ran on login pages and mailbox views, opened a WebSocket connection, removed browser cookies and identified selected government users for a fake Adobe update lure.
Symantec recorded more than one million implant check-in rows, more than 580,000 stolen browser cookies and more than 2,300 exfiltrated email bodies in the operator database. The injected script source was hxxps://fonts.chrorne[.]com/dist/js/12.qgfvjzvs.chunk.js. The fake update downloaded Antino from hxxps://microsoft-flash[.]com/download/Adobeinstall.exe. Antino used the Microsoft Graph API as a command-and-control channel. The installed PDF Viewer extension could access browser cookies, scripting, debugging, web requests, downloads and native messaging.
The malicious browser extension used the native-messaging registry path HKCU\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.microsoft.runedge. A published Antino SHA-256 is 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd. Published network indicators include microsoft-flash[.]com and 103[.]87[.]9[.]62. Attribution posture: Symantec assessed Jewelbug as a China-based hackers-for-hire group and linked its commercial arm with high confidence to a registered Hunan company, while saying the precise relationship between that individual and the espionage operators was not fully established.
Why this matters now
The central enterprise lesson is concentration at the presentation and identity layer. Jewelbug did not need to compromise each ministry separately; write access to a shared template turned one provider-level foothold into a watering hole across many tenants. Enterprises using hosted webmail, portals, identity pages or shared content-delivery components should identify equivalent places where one administrator or template can execute code for multiple organisations.
The campaign also shows why session containment cannot stop at password resets. The injected script stole browser cookies and observed new session tokens, while the malicious extension could intercept traffic and invoke browser functions. Where session material may have been copied, defenders need server-side token revocation, browser-profile review, endpoint investigation and validation of delegated permissions. A successful login after password rotation is not proof that an old session has been invalidated.
The published indicators give defenders concrete starting points, but indicator matching alone is incomplete. The operators used changing payloads, trusted cloud services and a selective lure that checked the victim’s government email domain and Windows status. Provider-side template integrity, unusual WebSocket activity, fake update execution and browser-extension persistence should therefore be investigated together.
The decision for security leaders
Assign web, identity, endpoint and provider-management owners to one investigation. Each team sees only part of the attack: template modification, session theft, fake-update execution, extension persistence and downstream authenticated access. A fragmented ticketing response risks closing one layer while another remains active.
Require hosted communications providers to identify every shared component capable of serving active content across tenants, who can modify it and how integrity is monitored. Provider assurance should include administrator-account review, change history, template comparison and a tenant-by-tenant statement of exposure.
Where indicators match, revoke sessions before relying on password changes, preserve browser artefacts and examine internal services reached from affected accounts. Leadership should define when shared-platform compromise triggers broad incident coordination even if only a small number of endpoint alerts are present.
Evidence of closure
- Provider change records prove shared webmail templates match an approved baseline.
- Session-revocation logs confirm affected identities have no surviving browser sessions.
- Endpoint evidence shows the Antino hash, PDF Viewer extension and registry path are absent.
- A tenant-scoped provider report documents administrator containment and affected-system boundaries.
The Security.io assessment
The strongest evidence comes from Symantec’s direct visibility into operator systems and its publication of concrete artefacts. The dataset counts are records, cookies and email bodies, not equivalent numbers of unique people or organisations. They nevertheless demonstrate realised collection rather than a list of intended targets.
The shared-provider compromise is the decision-changing element. It shows that template integrity and provider administrator identities can be as consequential as the security of the mailbox application itself. Enterprises should include these control points in identity architecture, third-party assurance and concentration-risk reviews.
Symantec’s attribution is detailed but deliberately bounded. The commercial operation is linked with high confidence to a named corporate representative, while the relationship to the espionage operators remains incompletely established. Security.io therefore treats the observed campaign and tooling as high-confidence findings without extending attribution to a government sponsor or unidentified customer.
Questions for the morning meeting
- Which shared webmail templates or provider-controlled assets can execute code across multiple tenants?
- Can identity teams revoke web sessions independently of password rotation?
- Do provider contracts require disclosure of administrator compromise and tenant-by-tenant containment evidence?