Symantec (Broadcom) Threat Hunter Team
symantec-broadcom · B · candidate
https://www.security.com/threat-intelligence
Added by the 2026-08-23 quality audit. Already cited by a published entry (2026-08-16 Jewelbug deep dive used security.com/threat-intelligence/jewelbug-crypto-fraud-espionage as primary) but never tracked, so it was found by search rather than swept. WebFetch on https://www.security.com/threat-intelligence returns a clean dated listing. Candidate — promote after 3 contributing runs.
Cited in 7 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 6).
- Two espionage toolsets shipped kernel-mode rootkits in the same week whose job is to edit what Windows reports to the defender's own tools — and one of them arrived on a zero-day that was patched on Tuesday2026-08-16
- Jewelbug: one script tag in a shared government webmail template put a watering hole on 15+ ministry tenants at once, and the browser extension it drops escapes the sandbox through a native-messaging host named after Microsoft Edge2026-08-16
- GodDamn ransomware (Beast/Monster rebrand) blinds EDR with 'PoisonX', a malicious kernel driver Microsoft signed2026-07-11
- DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)2026-06-17
- Symantec: five-month, low-and-slow mailbox-espionage campaign against a global stock exchange2026-06-04
- MuddyWater / Seedworm — Symantec and Carbon Black document new DLL-side-loading pair via signed Fortemedia and SentinelOne binaries, ChromElevator for Chromium App-Bound Encryption bypass, Node.js orchestration2026-05-28
- Symantec / Carbon Black document Fast16 hook engine targeting LS-DYNA/AUTODYN nuclear-simulation codes; Kim Zetter corrects "pre-Stuxnet" framing to contemporaneous-and-simulation-sabotage2026-05-19