2026-08-16HIGHA hack-for-hire group hit 15+ government webmail tenants with one script tag, then escaped the browser via a fake Edge helper
XG-Web
tool · tool:xg-web single-source
Jewelbug's browser-centric remote-access and information-stealing control panel, a React front end over a Node.js backend with a MySQL database that doubles as the rendezvous point for victim implants. Its developers describe it in their own documentation as a 'penetration-testing platform', while its internal function names include browser hijacking, data theft and man-in-the-middle attack. It administers both the group's government-espionage campaigns and its cryptocurrency-fraud operation, and its victim database recorded more than one million implant check-in rows and more than 580,000 stolen browser cookies (Symantec Threat Hunter Team, 2026-08-13).
Coverage
1
first 2026-08-16 → last 2026-08-16
Latest activity
2026-08-16
A hack-for-hire group hit 15+ government webmail tenants with one script tag, then escaped the browser via a…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, defense, telco · regions: middle-east, apac
Sources cited
2
2 hosts
Defender insights
What each entry about XG-Web tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
used by
- JewelbugSymantec states both the espionage and crypto-fraud missions are administered from a single control panel, XG-Web
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (14 across 8 tactics)
14 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessDrive-by Compromise
- ExecutionCommand and Scripting Interpreter: Windows Command Shell · User Execution: Malicious File
- PersistenceSoftware Extensions: Browser Extensions · Modify Authentication Process: Pluggable Authentication Modules
- StealthRootkit
- Defense ImpairmentModify Authentication Process: Pluggable Authentication Modules
- Credential AccessInput Capture: Web Portal Capture · Steal Web Session Cookie · Modify Authentication Process: Pluggable Authentication Modules
- CollectionInput Capture: Web Portal Capture · Screen Capture · Clipboard Data · Browser Session Hijacking
- Command and ControlProxy · Web Service: Dead Drop Resolver · Web Service: Bidirectional Communication
Initial Access TA0001
T1189Drive-by Compromise×1
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
Execution TA0002
T1059.003Command and Scripting Interpreter: Windows Command Shell×1
Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
Persistence TA0003
T1176.001Software Extensions: Browser Extensions×1
Adversaries may abuse internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality to and customize aspects of internet browsers. They can be installed directly via a local file or custom URL or through a browser's app store - an official online platform where users can browse, install, and manage extensions for a specific web browser. Extensions generally inherit the web browser's permissions previously granted.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
T1556.003Modify Authentication Process: Pluggable Authentication Modules×1
Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts. PAM is a modular system of configuration files, libraries, and executable files which guide authentication for many services. The most common authentication module is <code>pam_unix.so</code>, which retrieves, sets, and verifies account authentication information in <code>/etc/passwd</code> and <code>/etc/shadow</code>.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
Stealth TA0005
T1014Rootkit×1
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
Defense Impairment TA0112
T1556.003Modify Authentication Process: Pluggable Authentication Modules×1
Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts. PAM is a modular system of configuration files, libraries, and executable files which guide authentication for many services. The most common authentication module is <code>pam_unix.so</code>, which retrieves, sets, and verifies account authentication information in <code>/etc/passwd</code> and <code>/etc/shadow</code>.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
Credential Access TA0006
T1056.003Input Capture: Web Portal Capture×1
Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
T1539Steal Web Session Cookie×1
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
T1556.003Modify Authentication Process: Pluggable Authentication Modules×1
Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts. PAM is a modular system of configuration files, libraries, and executable files which guide authentication for many services. The most common authentication module is <code>pam_unix.so</code>, which retrieves, sets, and verifies account authentication information in <code>/etc/passwd</code> and <code>/etc/shadow</code>.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
Collection TA0009
T1056.003Input Capture: Web Portal Capture×1
Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
T1113Screen Capture×1
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
T1115Clipboard Data×1
Adversaries may collect data stored in the clipboard from users copying information within or between applications.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
T1185Browser Session Hijacking×1
Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
Command and Control TA0011
T1090Proxy×1
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
T1102.001Web Service: Dead Drop Resolver×1
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
T1102.002Web Service: Bidirectional Communication×1
Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.
Evidence: 2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole · ATT&CK page ↗
Entries about XG-Web (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Antino×1
- ClientKing×1
- Google Chrome×1
- Jewelbug×1
- Mozilla Firefox×1
- PDF Viewer (Jewelbug browser extension)×1
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (50%)
- security.com1 (50%)