Researchers have identified an advanced persistent threat (APT) group for hire in China that performs both international cyber espionage and lowly cryptocurrency theft.
With one hand, the mercenary group "Jewelbug" steals cryptocurrency from ordinary people online. With the other, it takes on jobs that must surely be at the behest of a nation-state, most likely China, according to new research from Symantec. The APT group performs both functions from a single, custom command-and-control (C2) panel, switching back and forth with the same ease as jumping between browser tabs. And it's equally accomplished in both ventures, managing hundreds of fake cryptocurrency exchanges while compromising government, military, and telecommunications organizations in Asia and the Middle East.
"This is quite different to cases where we’ve seen state-sponsored actors dabbling in cybercrime to make a little extra money," says Dick O'Brien, principal intelligence analyst for the Symantec Threat Hunter Team. "The sheer scale of the fraud business is the biggest clue. They aren't just making a little extra money by moonlighting."
Jewelbug's Tools and TTPs
Jewelbug campaigns rely on three primary, custom malware implants. There's a Windows backdoor, "Antino," and a Linux backdoor, "ClientKing," most often seen in cyber-espionage attacks.