Jewelbug APT Exploits Browsers to Infiltrate Government Networks

A sophisticated cyber espionage group known as Jewelbug has been exploiting web browsers to infiltrate government networks across the Middle East, Southeast Asia, and South Asia. By compromising government webmail systems and stealing browser cookies, the group has gained unauthorized access to sensitive information and monitored activities within these networks.

In a notable incident, Jewelbug injected malicious scripts into over 15 government webmail platforms, enabling them to access officials’ accounts. This operation led to the theft of more than 580,000 browser cookies, thousands of credentials, and over 2,300 email bodies, providing the attackers with a wealth of confidential data.

Browser Hijacking Techniques

Central to Jewelbug’s strategy is the deployment of XG-Web, a control system that allows remote manipulation of infected browsers. The group disseminated a malicious browser extension named “PDF Viewer,” which, under the guise of a document reader, requested extensive permissions. Once installed, this extension could read cookies, monitor session tokens, access browsing history and bookmarks, capture screenshots, and record clipboard contents.

The stolen cookies enabled the attackers to hijack active sessions, potentially bypassing multi-factor authentication measures. Additionally, the extension injected malicious code into websites and intercepted browser traffic. It communicated with a Windows component disguised as “com.microsoft.runedge” to execute commands on the compromised device.

Expanding the Attack Surface

Beyond browser exploitation, Jewelbug employed the Antino backdoor, which was delivered through deceptive Adobe Flash or installer downloads encountered during visits to compromised webmail sites. Antino utilized Microsoft Graph API traffic for command and control, while the browser extension provided real-time insights into the victim’s online activities.

The group also deployed ClientKing, a Linux-based implant targeting routers and servers, allowing them to extend their reach beyond individual devices to broader network infrastructure.

Watering Hole Attacks on Government Platforms

Jewelbug’s most extensive campaign involved a shared government webmail platform in the Middle East. By embedding malicious scripts into the hosting environment, the group transformed legitimate login and mailbox pages into conduits for their attacks. This method, known as a watering hole attack, is particularly effective as it exploits trusted services to reach high-value targets.

The injected script collected cookies and identified users through their government email addresses. It selectively displayed fake update prompts to Windows users within targeted domains, facilitating further compromise. In one instance, the attackers captured authenticated traffic to a virtualization management service, indicating that browser exploitation served as a gateway to internal infrastructure.

Jewelbug’s activities underscore the evolving nature of cyber threats, where browser-based attacks serve as entry points to more extensive network intrusions. Organizations must remain vigilant, regularly update their security protocols, and educate users about the risks associated with browser extensions and unsolicited downloads to mitigate such threats.