Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months

A five-month intrusion targeting a Russian IT service provider has been linked to a threat actor with ties to China, marking the hacking group’s entry into the nation outside of Southeast Asia and South America.

Symantec, owned by Broadcom, has linked the January–May 2025 activity to a threat actor it monitors as Jewelbug, claiming that it overlaps with clusters called CL-STA-0049 (Palo Alto Networks Unit 42), Earth Alux (Trend Micro), and REF7707 (Elastic Security Labs).

Despite growing military, economic, and political ties between Moscow and Beijing over the years, the results indicate that China is still able to conduct cyber espionage operations in Russia.

In a report shared with The Hacker News, the Symantec Threat Hunter Team claimed that attackers had access to software development systems and code repositories that they would use to launch supply chain assaults against the company’s Russian clients read more about Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *