Jewelbug crypto fraud exposed: 580,000 stolen cookies behind fake exchanges

NewsThu, 13 Aug 2026 15:29:38 UTC1 hour ago
Jewelbug crypto fraud exposed: 580,000 stolen cookies behind fake exchanges

A hacking crew that spends its days spying on governments and its nights running fake crypto exchanges sounds like something out of a heist movie. But according to new research from Broadcom’s Symantec Threat Hunter Team, that is exactly the profile of Jewelbug, a China-based hacker-for-hire group now drawing attention for blending state-linked espionage with large-scale Jewelbug crypto fraud operations aimed squarely at everyday cryptocurrency users.

Key takeaways

  • Jewelbug is a China-based hacker-for-hire group running parallel espionage and cryptocurrency fraud campaigns from a single command-and-control panel.
  • Its crypto scheme relies on AI-generated fake exchange pages and hundreds of lookalike domains impersonating Binance and OKX.
  • Symantec found the group also compromised government, military and telecommunications targets across Asia and the Middle East, plus a major US industrial and aerospace manufacturer.
  • Researchers uncovered more than 580,000 stolen browser cookie sets and 2,300 exfiltrated email bodies tied to Jewelbug’s operations.
  • Symantec’s Dick O’Brien says the scale of the fraud business suggests this is far more than a side hustle for a state-linked actor.

Jewelbug’s Dual Cyber Operations

Jewelbug operates as a mercenary outfit that appears equally comfortable stealing state secrets as it is draining crypto wallets. Symantec’s researchers describe a group that switches between government espionage and cryptocurrency fraud “with the same ease as jumping between browser tabs,” managing both lines of work from one custom-built control panel.

… Continue reading the full article at the original source below.

Read from Source · en.cryptonomist.ch ↗
This content is automatically aggregated. Full credit goes to the original publisher (en.cryptonomist.ch).

Related