NordVPN Promotion

Home / Industry

Jewelbug Targets the Middle East and Asia via Cyber Espionage and Crypto Fraud Campaigns

Security.com recently published an analysis of a China-based hackers-for-hire group Jewelbug espionage con crypto fraud campaign that trailed their sights on victims across the Middle East and Asia. The attackers administered both campaigns from a single control panel. And as of publishing, the group’s victim database recorded 1 million+ implant check-ins and 580K+ stolen browser cookies in less than three months of active operations.

The researchers publicized 27 network IoCs comprising 10 subdomains, five domains, and 12 IP addresses. We extracted unique domains from the subdomain IoCs then determined if any were owned by legitimate companies aided by the WhoisXML API MCP Server. We ended up with 10 domains; adding those to the 10 subdomains and 12 IP addresses identified as IoCs, we had 32 network IoCs in all for our DNS deep dive.

Our investigation led to these discoveries:

  • 670 distinct IP addresses potentially owned by victims that communicated with eight of the IP IoCs
  • 5,331 email-connected domains, one was confirmed malicious
  • Three additional IP addresses, two were confirmed malicious
  • Four IP-connected domains
  • 74 string-connected domains, three were confirmed malicious

A sample of the additional artifacts obtained from our analysis is available for download from our website.

Jewelbug Subdomain IoCs Scrutinized

We kicked off our analysis by scrutinizing the 10 subdomain IoCs. We queried them on several of our tools via the WhoisXML API MCP Server. Take a look at more information on five of them below.

SUBDOMAIN IoCWXA MCP SERVER FINDING
browser-update[.]pages[.]devDespite being hosted on a legitimate apex domain, it was a confirmed malware host, specifically associated with a SocGholish-style fake browser update lure hosted on free Cloudflare pages.
eastus2[.]wac-azure[.]comIt was designated suspicious since it could be mimicking the Microsoft Azure domain.
fonts[.]chrorne[.]comIt was designated suspicious since it could be abusing the Chrome brand.
d2nq35tel3ucuo[.]cloudfront[.]netDespite being hosted on a legitimate apex domain, it was dubbed a malware distributor.
ns1[.]jkskhei[.]comIt was tagged as malicious and could be imitating a nameserver.

It is also interesting to note that the subdomain IoCs could be categorized into three clusters described in greater detail below.

SUBDOMAIN IoC CLUSTERSUBDOMAIN IoCsRISK ASSESSMENT
Reputable cloud platform abusebrowser-update[.]pages[.]dev; d2nq35tel3ucuo[.]cloudfront[.]net; pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev; r6fi2yvqql.execute-api[.]ap-southeast-2[.]amazonaws[.]comHigh risk; two were active malware hosts; two were considered suspicious
Namecheap + WithheldForPrivacy + Cloudflarefonts[.]chrorne[.]com; ns1[.]jkskhei[.]com; robot[.]avbliud[.]comHigh risk; shared operator tradecraft; one was an active malware host
Gname registrareastus2[.]wac-azure[.]com; fonts[.]tarotfree101[.]top; dns[.]wizkidblogger[.]comModerate to high risk; typosquatting or staging infrastructure

Jewelbug Domain IoCs Dissected

Next, we looked more closely at the 10 domain IoCs. We began by querying them on WHOIS API and filling in gaps with data from Domain Info API. We discovered that:

  • They were created between 21 December 2020 and 21 April 2026, indicating that the threat actors did not discriminate in terms of domain age.
  • They were administered by five registrars.

  • While one did not have a registrant country on record, the remaining nine were registered in three countries.

We then queried the domain IoCs on DNS Chronicle API and found out that eight recorded 898 historical domain-to-IP resolutions over time. Here are more details about five examples.

DOMAIN IoCNUMBER OF DOMAIN-TO-IP RESOLUTIONSDATES SEEN
wizkidblogger[.]com33802/07/17–06/30/25
mailbycloud[.]com30402/06/17–03/10/25
wps-cn[.]com14903/29/17–08/12/26
f1ash[.]org[.]cn5311/12/21–12/13/25
wac-azure[.]com2412/10/25–07/16/26

At least three of the domains had resolutions dating as far back as 2017. They may have been reregistered to become part of the threat infrastructure.

Jewelbug IP IoCs Investigated

Next, we zoomed in on the 12 IP IoCs. First, sample network traffic data from the IASC revealed that 670 unique IP addresses potentially owned by victims under 52 distinct ASNs communicated with eight of the IP IoCs from 2 March to 4 August 2026.

We then queried the IP IoCs on Bulk IP Geolocation Lookup and discovered that:

  • They were geolocated in five countries, two of which—China and the U.S.—were also among the domain IoCs’ registrant countries.
  • While four did not have ISPs on record, the remaining eight were administered by four ISPs.

After that, we queried the IP IoCs on DNS Chronicle API and found out that seven posted 1,566 historical IP-to-domain resolutions over time. Take a look at more information about five examples below.

IP IoCNUMBER OF IP-TO-DOMAIN RESOLUTIONSDATES SEEN
43[.]246[.]208[.]17965008/02/24–08/18/26
43[.]246[.]208[.]23636602/05/17–03/29/25
167[.]71[.]195[.]25525808/03/19–02/27/26
219[.]76[.]254[.]18423202/06/17–03/27/26
103[.]87[.]9[.]625706/03/18–11/22/24

Several of the IP IoCs stopped recording resolutions before 2026.

New Jewelbug Artifacts Amassed

Next, we scoured the DNS for artifacts that could be tied to the Jewelbug attack. First, we queried the domain IoCs on WHOIS History API. We learned that seven had 18 unique email addresses in their historical records.

Upon further scrutiny, we determined that 10 were public email addresses but one could potentially belong to a domainer. That said, we continued our analysis for only nine public email addresses. We queried them on Reverse WHOIS API, which led to the discovery of 5,331 distinct email-connected domains after those already dubbed as IoCs were filtered out.

We queried the email-connected domains on Threat Intelligence API and discovered that one—q-vpn[.]com—has already been weaponized to distribute malware since 27 January 2025.

We also queried the email-connected domains on Domain Traffic API and identified 10 with the highest number of visits.

Check out more 2026 information about the 10 most visited email-connected domains below.

EMAIL-
CONNECTED DOMAIN
JANFEBMARAPRMAYJUNJULAUGSEPTOTAL
huayangtg[.]com3,4353,2723,3181,6111,4061,067871091414,319
xjnlq[.]com7627139009537048192,196994248,065
5d5d9[.]com900508930836791985938874206,782
aaeyinli[.]com6373865045304709631,1561,039315,716
wavku[.]com5144016355987716511,083745955,493
wcwj[.]net445629488408409612584858254,458
pepscn[.]com452441628360280355431784263,757
szheu[.]com44142054049332945936925773,315
xcaf[.]net32223730831330028529424272,308
999041[.]com000003211,010941292,301

It is interesting to note that despite being seemingly DGA domains, the artifacts have been visited a lot even to this day. We also mapped out when each email-connected domain received the highest number of daily visits.

This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By WhoisXML API, A Domain Research, Whois, DNS, and Threat Intelligence API and Data Provider —

Whois API, Inc. (WhoisXML API) is a big data and API company that provides domain research & monitoring, Whois, DNS, IP, and threat intelligence API, data and tools to a variety of industries.

Visit Page

Filed Under

Comments

Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Brand Protection

Sponsored byCSC

DNS Security

Sponsored byWhoisXML API

IPv4 Markets

Sponsored byIPv4.Global

New TLDs

Sponsored byRadix

DNS

Sponsored byDNIB.com

Domain Names

Sponsored byVerisign

Cybersecurity

Sponsored byVerisign

NordVPN Promotion