A China-linked hacking group called Jewelbug compromised a shared government webmail system and used it to spy on officials across 15 government tenants in a Middle Eastern country. Symantec says the attackers gained write access to a shared webmail installation run through a state telecom provider and national services agency, injected malicious JavaScript into common templates, stole session cookies and email data, and selectively pushed the Antino backdoor and a malicious PDF Viewer browser extension to high-value government users. The same XG-Web control panel was also used to run large-scale cryptocurrency fraud.
Why it matters: Government agencies and military-linked users may have had their email sessions and credentials stolen without noticing, creating risks of long-term espionage and follow-on compromise. Organizations using shared webmail or state-hosted platforms should urgently check for template tampering, invalidate sessions and cookies, review browser-extension installs, and hunt for Antino and related infrastructure.
Bill Toulas
2026.08.13
100% relevant
This article establishes a distinct intrusion and espionage campaign centered on Jewelbug's compromise of a shared government webmail platform affecting 15 government tenants, with no clearly matching existing tracked story for the same underlying event.
← Back to all stories