Chinese hacker group breaches 15 govt webmail accounts while running crypto fraud scheme

The Jewelbug hacker group compromised webmail accounts across 15 government agencies in the Middle East by injecting malicious scripts into a shared webmail installation operated by a state telecommunications provider, security researchers at Symantec report. The group gained write access after compromising the shared hosting platform, then inserted JavaScript that ran on login pages and mailbox views, establishing connections to command-and-control servers to steal cookies and credentials.
Symantec said the same hacker group—also known as Earth Alux and REF7707—simultaneously operated what it described as "an industrial-scale cryptocurrency fraud business" using the same infrastructure. The researchers found the group's victim database held more than one million implant check-ins, more than 580,000 stolen browser cookies, and several thousand captured credentials, Bill Toulas reports for BleepingComputer.