ZeroHour

Search: “broadcom”

5 stories

Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations

Broadcom researchers link the Chinese APT group 'Jewelbug' to a lucrative crypto-fraud hack-for-hire operation.

Threat intelligence researchers at Broadcom reported that the known Chinese APT group tracked as Jewelbug may be connected to a profitable crypto fraud scheme. The findings suggest the group blends traditional espionage tradecraft with financially motivated hack-for-hire work. Victimology and operational scale were not detailed in the initial disclosure.

Infosecurity Magazine · Aug 14, 2026Threat actor

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Symantec reports multiple threat actors, including KongTuke, abusing the trusted signed Node.js runtime and blockchain C2 (EtherHiding) to deliver backdoors in targeted attacks.

Symantec's Threat Hunter Team (Broadcom) reports that since February 2026 attackers have used the legitimate signed node.exe binary and interpreted scripts to deliver implants while evading signature-based detection, hitting government departments, technology companies, and hotels. One intrusion at an Asian technology firm (March 23–July 25, 2026) used ClickFix social engineering, the official Node.js installer, and EtherHiding to fetch commands via the Ethereum blockchain after AdaptixC2 and Cobalt Strike attempts were blocked. Related chains involve KongTuke (Woodgnat) using ModeloRAT, Mistic, NexShield, and GateKeeper, plus C2Looper, AsukaStealer, and EtherRAT; GuidePoint Security separately linked a fake-CAPTCHA ClickFix campaign to at least 31 compromised organizations using the Polygon blockchain as a dynamic C2 address book.

The Hacker News · 13d agoThreat actor in the wild1