
A China-linked mercenary hacking group has been simultaneously running government espionage operations across the Middle East, South Asia, and Southeast Asia and defrauding Chinese-speaking cryptocurrency users — from the exact same dashboard, on the same servers, administered by the same small team. The group, designated Jewelbug by Broadcom’s Symantec Threat Hunter Team and also tracked as Earth Alux, REF7707, and CL-STA-0049 by competing research labs, has been active since at least the second quarter of 2023 — but the full scope of what it built became clear only through a months-long investigation whose findings Symantec published August 13, 2026.
The most concrete finding from that investigation is…







