grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

One Script Tag Exposed 15 Government Webmail Tenants

government webmail breach
Published on
August 19, 2026

A China-based hacking group planted a single script tag inside a shared hosting platform, and the resulting breach exposed webmail accounts belonging to 15 government tenants at once. The platform served ministries and agencies across one Middle Eastern country, jointly run by the state telecom provider and the national services agency.

Researchers who later mapped the operation found something stranger than a standard spying campaign. The same team ran an industrial-scale cryptocurrency fraud business from the same control panel and the same servers, switching between the two jobs. That combination points to a hack-for-hire outfit selling espionage while monetising its own tooling on the side.

How the government webmail breach unfolded

The group obtained write access to the shared webmail installation, which let it modify the common template every tenant loaded. From that point, the breach reached every login page and mailbox view on the government webmail platform. Nine separate domains fell inside its reach without any further intrusion.

Each time a user signed in, the injected script opened a WebSocket connection to a command and control server. It stole webmail cookies, then read the account holder's address and checked it against a list of targeted government domains. Accounts outside that list received no payload, which kept the operation quiet.

Valuable targets received a fake Adobe Flash update prompt instead. Accepting it installed a Windows backdoor called Antino, along with browser tools built for credential and session theft.

A toolkit built for browsers and network gear

Antino also arrives through malicious HTA files and fake Adobe installers, and once running it pulls down further payloads. One of those is a browser extension named PDF Viewer, built for Chrome and Firefox.

The extension steals cookies and credentials, intercepts traffic, injects JavaScript, and hands operators remote control of browser functions. A clipboard module inside it swaps cryptocurrency wallet addresses mid transaction, so victims paste an attacker-controlled address without noticing.

A second implant called ClientKing targets Linux servers, ARM64 devices, and ASUS routers. Written in Rust, it handles command execution, SOCKS proxying, DNS tunnelling, and in-memory kernel module loading. The operators also parked obfuscated payloads on public Google Docs, so implant traffic blended into ordinary cloud activity.

The scale investigators uncovered

Researchers traced infections back to the group's own infrastructure and gained visibility into its management platform, database, server logs, and source code. That access turned a routine malware hunt into a full inventory of the operation.

The victim database holds more than one million implant check-in rows, over 580,000 stolen browser cookies, several thousand captured credentials, and more than 2,300 exfiltrated email bodies. Runtime logs recorded roughly 1.1 million geolocation events across about 4,300 distinct source addresses.

Around 87,200 of those connections came from one Southeast Asian country, covering state telecom and military networks. Another 53,100 traced to a Middle Eastern country, including Starlink-connected addresses in the capital. A further 15,000 reached government ministry infrastructure in a second Southeast Asian nation, and campaign records list more than 90 police and government email addresses across South Asia. Numbers on that scale explain why a breach of government webmail carries weight beyond one country.

Espionage and crypto fraud on a single panel

The financial arm of the operation runs almost entirely on automation. A pipeline scrapes keywords, generates thousands of fake download pages with AI, and publishes them across a 44-server content management fleet. Hundreds of lookalike domains impersonate OKX and Binance, while click bots push those pages up the search rankings.

The same infrastructure also supports sports betting lures, pirated livestream portals, and private detective scams aimed at Chinese-speaking victims. Researchers attribute the financially motivated side with high confidence to a Chinese company advertising SEO services, and one operator connects through identity documents to a registered business in Hunan Province.

The governments caught in this webmail breach faced a commercial contractor rather than a uniformed intelligence unit. The same people spent their other hours draining crypto wallets, which changes how long defenders should expect them to persist.

Why shared hosting turns one intrusion into many

Consolidating mail for multiple ministries onto a single platform saves money and simplifies administration. It also creates one point of failure for every tenant on it. When agencies share a host, the security posture of that host becomes their own.

No software vulnerability appears anywhere in this attack chain, because the group simply gained write access to the platform. Everything afterwards followed from ordinary functionality. Patch cycles offer no defence against an attack built entirely from features working as designed.

Detection presents the harder problem, since a script served by the site users already trust raises no warning. Staff logging into a breached government webmail portal see exactly the interface they expect. Cookie theft happens before anyone finishes typing a password.

What defenders can act on

Integrity monitoring on shared templates catches unauthorised edits within minutes rather than months, and Content Security Policy headers block scripts loading from unapproved origins. Anyone running webmail for multiple government tenants should assume that a breach of the platform equals a breach of every tenant on it, so segmentation between tenants matters as much as perimeter defence.

The line between statecraft and crime keeps thinning

Contractors now sell access to governments in the morning and monetise the same tooling against retail crypto users in the afternoon. Defenders who sort threats into neat categories of espionage or cybercrime will misjudge both motive and persistence.

A breach that reaches government webmail affects citizens as well, since ministries handle tax records, permits, licences, and legal correspondence. Stolen mailboxes expose the people who wrote to those ministries, not only the officials who received them.

The breach of government webmail accounts across 15 tenants began with one script tag in one template. That economy of effort remains the most instructive detail in the case.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.