Hackers Compromise 15 Government Webmail Tenants and Run Parallel Crypto Fraud
What Happened – The China‑based Jewelbug (aka Earth Alux/REF7707) gained write access to a shared webmail platform used by 15 government tenants. A malicious script was injected into the common email template, exfiltrating cookies, credentials and email bodies, and delivering the Antino backdoor and a fake Flash update to install additional payloads. The same control panel was used to run a large‑scale cryptocurrency fraud operation.
Why It Matters for Compliance & Audit Readiness
- This attack illustrates a failure of access‑control and segregation‑of‑duties safeguards that SOC 2’s Security and Confidentiality principles require.
- Continuous evidence of who can modify shared SaaS configurations, and how those changes are reviewed, is essential to demonstrate due‑diligence in an audit.
- The incident underscores the need for documented credential‑management policies and regular security‑awareness training to detect malicious scripts in user‑facing templates.
Who Is Affected – Government agencies (defense, telecommunications, education, aviation) across the Middle East, Southeast Asia and South Asia; the underlying SaaS email provider’s multi‑tenant infrastructure.
Recommended Actions –
- Map the compromised webmail configuration change to SOC 2 Control CC6.1 (Logical Access Controls) and collect change‑management logs as audit evidence.
- Implement continuous monitoring of SaaS admin actions and enforce least‑privilege for template editing.
- Conduct a targeted security‑awareness refresher for administrators handling shared services.
Source: BleepingComputer
Technical Notes – The attackers inserted a malicious JavaScript payload into the shared email template, which opened a WebSocket to a C2 server, stole cookies, and delivered the Antino HTA backdoor via a fake Adobe Flash installer. Additional payloads included a browser‑extension “PDF Viewer” that intercepted traffic and exfiltrated credentials. Source: Symantec analysis (linked above)