UAT-11587 is the Jewelbug APT running espionage and crypto fraud
Assessment
Symantec's research of August 13, 2026 attributes the Antino-related espionage to a named China-based APT it calls Jewelbug (aka Earth Alux, REF7707, CL-STA-0049) and ties it to a parallel cryptocurrency-fraud business run by the same team. Cisco Talos, in its September 30, 2026 report, states it 'identified overlaps' but 'could not independently verify a connection between the espionage campaign and Jewelbug's financially motivated activity,' and therefore tracks UAT-11587 as a separate activity set. Treating the two as the same named group goes beyond what Talos confirmed.
Where this claim appeared
Symantec (Broadcom) · 2026-08-13
https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionageWhat “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
UAT-11587 deploys Antino backdoor using Microsoft 365 as dead-drop C2 against Asian governmentsThink this assessment is wrong? Report an error.