Researchers linked Jewelbug’s cyber espionage and crypto fraud operations to shared infrastructure, while DNS analysis uncovered thousands of connected domains, hundreds of potential victim IP addresses and additional malicious artifacts.