Threat researchers at Symantec and Carbon Black said the activity ran from November 2025 to mid-February, with evidence that ...