ThreatPaper
Assessed, Not Confirmed

UAT-11587 is the Jewelbug APT running espionage and crypto fraud

Assessment

Symantec's research of August 13, 2026 attributes the Antino-related espionage to a named China-based APT it calls Jewelbug (aka Earth Alux, REF7707, CL-STA-0049) and ties it to a parallel cryptocurrency-fraud business run by the same team. Cisco Talos, in its September 30, 2026 report, states it 'identified overlaps' but 'could not independently verify a connection between the espionage campaign and Jewelbug's financially motivated activity,' and therefore tracks UAT-11587 as a separate activity set. Treating the two as the same named group goes beyond what Talos confirmed.

Where this claim appeared

Symantec (Broadcom) · 2026-08-13

https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

UAT-11587 deploys Antino backdoor using Microsoft 365 as dead-drop C2 against Asian governments

Think this assessment is wrong? Report an error.