A newly identified advanced persistent threat (APT) group, known as Jewelbug, has been found to be engaging in both state-sponsored espionage and cryptocurrency theft. This unique dual-motivation approach allows the group to balance its financial interests with its obligations to state-aligned actors. Researchers have observed Jewelbug operating from a single web panel, facilitating both types of activities. The group's ability to navigate these two distinct objectives raises concerns about the evolving nature of threat actor motivations. The use of a single platform for both espionage and financial gain suggests a high degree of organizational sophistication. This blurring of lines between state-aligned and financially motivated threat activity has significant implications for the broader cybersecurity landscape1. The discovery of Jewelbug's operations highlights the need for practitioners to consider the potential for multiple motivations behind a single threat actor's activities, making threat assessment and mitigation more complex.