Threat Actor ๐Ÿ‡จ๐Ÿ‡ณ China

REF7707

Also known as: CL-STA-0049 ยท Jewelbug

REF7707 is a cyber campaign targeting government entities, particularly a foreign ministry in South America, utilizing malware families such as FinalDraft, GuidLoader, and PathLoader for persistence and lateral movement. The threat actor employs the Microsoft Graph API for C2 communication, blending malicious traffic with legitimate activity to evade detection. Despite their technical sophistication, REF7707 operators exhibited poor operational security, leading to the exposure of their infrastructure and malware. Their tactics enable the extraction of sensitive data, including passwords and Active Directory information, facilitating ongoing espionage activities.

Indicators of Compromise 53

Domain binance[.]com Domain browser-update[.]pages[.]dev Domain dns[.]wizkidblogger[.]com Domain eastus2[.]wac-azure[.]com Domain fonts[.]chrorne[.]com Domain fonts[.]tarotfree101[.]top Domain mailbycloud[.]com Domain microsoft-flash[.]com Domain ns1[.]jkskhei[.]com Domain okx[.]com Domain pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev Domain robot[.]avbliud[.]com Domain www[.]f1ash[.]org[.]cn Domain www[.]jkskhei[.]com Domain www[.]wps-cn[.]com Filename TEST.hta Filename Vb0c44dfslc.dll.wx Filename flashcenter_pp_ax_install_en.exe Filename slc.dll SHA-256 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a SHA-256 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd SHA-256 153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e SHA-256 297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561 SHA-256 30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d SHA-256 430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55 SHA-256 5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef SHA-256 5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac SHA-256 6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2 SHA-256 97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad SHA-256 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 SHA-256 ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813 SHA-256 b09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cf SHA-256 b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e SHA-256 d96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869 SHA-256 e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 SHA-256 e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf SHA-256 e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0 SHA-256 e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb SHA-256 e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 SHA-256 ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877 SHA-256 f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 IP 103[.]87[.]9[.]62 IP 129[.]212[.]237[.]224 IP 143[.]246[.]208[.]236 IP 152[.]42[.]174[.]15 IP 167[.]71[.]195[.]255 IP 219[.]76[.]254[.]184 IP 38[.]12[.]1[.]47 IP 43[.]246[.]208[.]179 IP 47[.]250[.]208[.]35 IP 47[.]84[.]37[.]113 IP 47[.]84[.]51[.]173 IP 47[.]87[.]71[.]167

MITRE ATT&CK TTPs 1

Source Articles

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug, a China-based APT group also known as Earth Alux or REF7707, conducts parallel espionage and cryptocurrency fraud operations using shared infrastructure and a unified control panel called XG-Web. The group targets government ministries in the Middle East, Southeast Asia, and South Asia through browser-based attacks and watering-hole compromises, while simultaneously running a for-profit crypto fraud scheme targeting Chinese-speaking users. Their primary malware includes the Antino Windows backdoor and a malicious 'PDF Viewer' browser extension, both deployed via fake software installers and HTA downloaders. The group leverages compromised hosting providers to scale attacks, stealing over 580,000 browser cookies and more than one million implant check-ins in under three months.
security-com ยท2w ago
Hackers breach govt webmail while running parallel crypto fraud
The China-based threat actor Jewelbug (also known as Earth Alux and REF7707) has been conducting espionage operations against government and military organizations in the Middle East, Southeast Asia, and South Asia, while simultaneously running a large-scale cryptocurrency fraud operation. The group compromised a shared webmail platform used by multiple government tenants, injecting a malicious script into login and mailbox pages to steal cookies and credentials. Successful compromises led to the deployment of the Antino backdoor via fake Adobe Flash installers, enabling further payload delivery, including a malicious browser extension called 'PDF Viewer' that steals credentials and injects JavaScript. Symantec uncovered the group's infrastructure, revealing over one million implant check-ins, more than 580,000 stolen browser cookies, and extensive cryptocurrency fraud operations using AI-generated content and lookalike domains impersonating Binance and OKX.
bleeping-computer ยท2w ago