started · updated
Cybersecurity reports expose Jewelbug espionage and JWR phishing framework
Security researchers have identified two distinct Chinese-linked cyber threats: the Jewelbug APT group and the JWR phishing framework.
Jewelbug, also known as Earth Alux, operates a dual-mission infrastructure that conducts both government espionage and for-profit cryptocurrency fraud. Using the XG-Web control panel, the group has targeted government ministries across the Middle East, Southeast Asia, and South Asia. Investigations by Symantec revealed that the group compromised a shared web-hosting platform to plant scripts across more than 15 government webmail tenants. The group’s database contains over one million implant check-ins, 580,000 stolen browser cookies, and thousands of captured credentials and email bodies.
Separately, Cisco Talos has detailed JWR, a Chinese-language Phishing-as-a-Service (PhaaS) framework. Unlike traditional static phishing pages, JWR utilizes AES-CTR encrypted WebSockets to stream credit card details and credentials to attackers in real-time as victims type them. The framework allows attackers to use over 40 different commands to dynamically trigger screen transitions, such as prompting for one-time passwords (OTPs) or secondary banking approvals, to bypass security measures.
Entities
Cisco Talos · JWR · Jewelbug · Symantec