A China-linked threat group tracked as Jewelbug has turned public Google Docs into a resilient command-and-control delivery channel, embedding freshly obfuscated malware payloads in documents that victim implants retrieve and execute. The technique allows malicious traffic to resolve through Google-owned infrastructure, helping the operators blend into legitimate web activity and potentially evade reputation-based filtering. Jewelbug, […]
Read the original article: