Tag: Symantec

  • One Script, 15+ Government Tenants: Why Shared Hosting Multiplies Espionage Risk

    One Script, 15+ Government Tenants: Why Shared Hosting Multiplies Espionage Risk

    TL;DR · 30-second read

    The Short Version

    Security researchers at Symantec say a small hacking crew based in China spent months reading the email of government officials across Asia and the Middle East. It also ran a cryptocurrency scam business from the same control screen.

    Its most effective move: instead of breaking into government ministries one at a time, it broke into the single company that hosted all of their email. One planted piece of code reached more than 15 government email systems at once.

    The takeaway is simple. When many organizations rely on one shared provider, one break-in can expose all of them.

    Industrial Cyber reported on August 14 that Symantec’s Threat Hunter Team, working with Carbon Black researchers, has exposed Jewelbug, which Symantec describes as a China-based hackers-for-hire group. According to Symantec, the group ran espionage campaigns against governments, militaries and state telecom operators across the Middle East, Southeast Asia and South Asia. It also ran a cryptocurrency fraud operation aimed at Chinese-speaking victims, and both activities were managed from a single browser-based control panel called XG-Web.

    In under three months, Symantec found, the group logged more than one million implant check-ins and stole over 580,000 browser cookies, thousands of credentials and more than 2,300 email bodies. An implant is a piece of malware that reports back to its operators. Its largest operation compromised a shared web-hosting platform run by a Middle Eastern state telecom provider, which placed malicious code in front of more than 15 government webmail tenants at once.

    Executive Summary

    Symantec’s research is unusually detailed. It is built on visibility into the group’s own control panel and victim database, so it describes more than a list of intended targets. It documents actual compromises: harvested mailboxes of senior officials, intercepted internal network traffic, and implants running on Windows machines, Linux servers and network devices. Jewelbug is also tracked under other names, including Earth Alux, REF7707 and CL-STA-0049.

    For infrastructure operators, the most important finding is architectural rather than about any single piece of malware. Jewelbug did not breach each ministry one by one. It gained write access to a centrally hosted webmail system run by a state telecom and planted one script, and that script fired for every ministry employee who logged in. A second finding points in the same direction. The group’s Linux and router implant, ClientKing, is built to reach servers and network equipment, the layer that carries everyone else’s traffic.

    Symantec also reported that some ClientKing builds were configured to route traffic through the internal corporate proxy of a major U.S. aerospace and industrial manufacturer. That extends the group’s footprint beyond Asia and the Middle East into industrial infrastructure.

    One Write Permission, Fifteen Ministries

    The shared-hosting compromise is the clearest demonstration in Symantec’s report of how multi-tenancy changes the economics of an attack. Multi-tenancy means many customers running on one platform. The Middle Eastern government’s ministries did not each run their own mail servers. They were tenants on a web-hosting platform operated by the state telecommunications provider. Once Jewelbug had write access to the central webmail system, it needed only one malicious script. That script ran each time any ministry staff member logged in or checked their email, across more than 15 government tenants.

    The attack chain that followed was conventional, and that is part of the lesson. The injected code captured session cookies and email addresses. Session cookies are the small tokens that keep a user logged in, and stealing one can let an attacker impersonate that user without a password. Windows users were then shown a fake Adobe Flash update prompt, which installed Antino, the group’s backdoor. Antino added a malicious browser extension that gave operators control of the browser and a route into internal government networks. None of these steps required a novel exploit against each ministry, because the shared platform had already delivered every tenant to the attacker.

    Symantec’s own summary makes the point directly: compromising a shared hosting provider and placing a watering hole on every government tenant turned a single intrusion into access across an entire national webmail estate. A watering hole is a trusted site rigged to infect the people who visit it. The implication for telecoms, hosting providers and data center operators that serve government or regulated customers is that the provider’s control plane is part of every tenant’s attack surface. The control plane is the administrative layer with write access to shared code. Tenant isolation at the data layer does little if one set of credentials can change the code all tenants run.

    The Network Layer Is in Scope

    Most espionage reporting centres on endpoints: laptops, email and browsers. Jewelbug’s toolkit goes further. According to Symantec, ClientKing is a Linux and router implant that can reach servers and network devices, and all of the group’s implants feed one victim database. Routers and Linux servers sit below the level where most endpoint detection tools operate. They often run for years between refreshes, and they see traffic from many downstream users at once.

    That matters for the telecom operators Symantec says were targeted. A foothold on network infrastructure can outlast a cleaned-up laptop and can observe traffic rather than just one user’s files. Symantec noted that the group intercepted internal network traffic, and that the common thread across its espionage targets was government communications and the providers that host them. The researchers said that combination would give an intelligence customer broad, durable access to official correspondence.

    The detail about the U.S. aerospace and industrial manufacturer needs careful reading. Symantec said a couple of ClientKing builds were configured to beacon through that company’s internal corporate proxy. That shows the group’s tooling was set up to operate inside or through that environment. The report as described does not establish the extent of any compromise there.

    A Hack-for-Hire Business Model, Visible From the Inside

    Symantec’s central attribution finding is that foreign-government espionage and commodity cryptocurrency fraud ran on the same infrastructure, by the same small team, from one control panel. The researchers call that pairing the signature of a hack-for-hire entity running for-profit crime on the side. They tied the fraud and search-engine-optimisation arm, with high confidence, to the sole legal representative of an SEO company in Changsha, Hunan Province. That attribution rests on identity documents, a business license and a stamped authorization letter. Symantec was explicit that the link between this individual and the espionage operators is not fully established. Its assessment is that the SEO business most likely supplied access, infrastructure and delivery.

    The operational discipline is notable for defenders. The group has built five generations of command-and-control code, the servers and software attackers use to direct their malware. A scheduled job checked its own domains against VirusTotal every 12 hours so operators could rotate away from anything flagged. VirusTotal is a widely used public malware-scanning service. Antino disguised its communications as ordinary Microsoft cloud traffic. Taken together, these choices suggest that blocklists and domain reputation alone will lag this kind of operator. Behavioural monitoring and integrity checks on shared code are better placed to catch it.

    For hosting and telecom operators, the practical questions are about blast radius. Who holds write access to code that every tenant executes? Is that code monitored for unauthorized changes? Are session tokens bound tightly enough that a stolen cookie is of limited use? None of these are exotic controls. The Jewelbug case shows what happens when one of them fails on a platform many customers share.

    Background

    Symantec is one of the longest-established names in enterprise security. Its enterprise business has been part of Broadcom since 2019, and its Threat Hunter Team publishes research on state-linked and criminal hacking groups alongside Carbon Black, another Broadcom-owned security brand. Different vendors often track the same group under different names, which is why Jewelbug also appears in industry reporting as Earth Alux, REF7707 and CL-STA-0049.

    Telecom operators and hosting providers have long been attractive espionage targets because they sit upstream of many customers at once. Governments in many regions consolidate ministry email and web services onto shared platforms, often run by a state telecom, to cut cost and complexity. The Jewelbug case shows the other side of that trade-off: consolidation also concentrates risk. Earlier in 2026, Symantec reported on Seedworm, an Iran-linked group whose campaigns spanned government, airport, manufacturing and financial targets.

    Sources

    Source: Symantec reveals Jewelbug espionage campaign targeting Asian governments, telecoms, critical infrastructure (Industrial Cyber): coverage of Symantec’s findings on a China-based hack-for-hire group running espionage and cryptocurrency fraud from one control panel.