Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months
A five-month intrusion targeting a Russian IT service provider has been linked to a threat actor with ties to China, marking the hacking group's entry into the nation outside of Southeast Asia and South America.
Symantec, owned by Broadcom, has linked the January–May 2025 activity to a threat actor it monitors as Jewelbug, claiming that it overlaps with clusters called CL-STA-0049 (Palo Alto Networks Unit 42), Earth Alux (Trend Micro), and REF7707 (Elastic Security Labs).
Despite growing military, economic, and political ties between Moscow and Beijing over the years, the results indicate that China is still able to conduct cyber espionage operations in Russia.
In a report shared with The Hacker News, the Symantec Threat Hunter Team claimed that attackers had access to software d...










