<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — Malware</title><description>Cybersecurity articles in Malware on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Fuyao Operation: Android TV Boxes Mimic Phones, Hijack Bandwidth</title><link>https://runtimerebel.com/blog/fuyao-operation-android-tv-boxes-mimic-phones-hijack-bandwidth</link><guid isPermaLink="true">https://runtimerebel.com/blog/fuyao-operation-android-tv-boxes-mimic-phones-hijack-bandwidth</guid><description>Cheap Android TV boxes are pre-installed with Fuyao malware, impersonating phones for ad fraud and turning devices into residential proxy nodes.</description><pubDate>Fri, 31 Jul 2026 17:41:21 GMT</pubDate><category>Fuyao</category><category>Android TV Box</category><category>Ad Fraud</category><category>Proxy Network</category><category>Zhejiang Fengwo IoT Technology Co Ltd</category><category>Supply Chain Compromise</category><category>Mobile Impersonation</category></item><item><title>Astaroth&apos;s Spambot Component: Expanding Phishing and Exfiltration</title><link>https://runtimerebel.com/blog/astaroth-s-spambot-component-expanding-phishing-and-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/astaroth-s-spambot-component-expanding-phishing-and-exfiltration</guid><description>Analysis of Astaroth trojan&apos;s new spambot component, detailing its capabilities for email harvesting, spam distribution, and data exfiltration tactics.</description><pubDate>Thu, 30 Jul 2026 06:30:05 GMT</pubDate><category>Astaroth</category><category>Spambot</category><category>Malware</category><category>Phishing</category><category>Data Exfiltration</category><category>Threat Intelligence</category></item><item><title>SSH Botnet Reconnaissance Before Linux Cryptominer Deployment</title><link>https://runtimerebel.com/blog/ssh-botnet-reconnaissance-before-linux-cryptominer-deployment</link><guid isPermaLink="true">https://runtimerebel.com/blog/ssh-botnet-reconnaissance-before-linux-cryptominer-deployment</guid><description>An SSH botnet performs extensive hardware and system reconnaissance on Linux targets before deploying an optimized cryptocurrency miner. Weak credentials exploited.</description><pubDate>Thu, 30 Jul 2026 02:32:56 GMT</pubDate><category>SSH Botnet</category><category>Cryptomining</category><category>Linux</category><category>XMRig</category><category>Pnscan</category><category>Brute Force</category></item><item><title>Flying Eagle Mobile RAT Builder: China&apos;s Infostealer-as-a-Service</title><link>https://runtimerebel.com/blog/flying-eagle-mobile-rat-builder-china-s-infostealer-as-a-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/flying-eagle-mobile-rat-builder-china-s-infostealer-as-a-service</guid><description>Analysis of the &apos;Flying Eagle&apos; mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…</description><pubDate>Thu, 30 Jul 2026 02:32:07 GMT</pubDate><category>Flying Eagle</category><category>Mobile RAT</category><category>Android Malware</category><category>Infostealer</category><category>Malware as a Service</category><category>Financial Fraud</category><category>China</category></item><item><title>Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence</title><link>https://runtimerebel.com/blog/tengu-botnet-exploits-linux-watchdog-for-reboot-based-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/tengu-botnet-exploits-linux-watchdog-for-reboot-based-persistence</guid><description>The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.</description><pubDate>Tue, 28 Jul 2026 17:36:22 GMT</pubDate><category>Tengu</category><category>Mirai</category><category>Linux Botnet</category><category>Iot Security</category><category>DDoS</category></item><item><title>Dysphoria Botnet: 200K Devices Engaged in DDoS and Traffic Relay</title><link>https://runtimerebel.com/blog/dysphoria-botnet-200k-devices-engaged-in-ddos-and-traffic-relay</link><guid isPermaLink="true">https://runtimerebel.com/blog/dysphoria-botnet-200k-devices-engaged-in-ddos-and-traffic-relay</guid><description>Analysis of the Dysphoria DDoS botnet, which has compromised 200,000 devices globally for denial-of-service attacks and traffic relay operations. Learn mitigation.</description><pubDate>Mon, 27 Jul 2026 21:12:36 GMT</pubDate><category>Dysphoria</category><category>Botnet</category><category>DDoS</category><category>Traffic Relay</category><category>Malware</category></item><item><title>Dysphoria Botnet Adopts Blockchain C2 for Enhanced IoT Resilience</title><link>https://runtimerebel.com/blog/dysphoria-botnet-adopts-blockchain-c2-for-enhanced-iot-resilience</link><guid isPermaLink="true">https://runtimerebel.com/blog/dysphoria-botnet-adopts-blockchain-c2-for-enhanced-iot-resilience</guid><description>Dysphoria IoT botnet evolves with blockchain-based C2 and victim relays after JackSkid disruption, posing new challenges for defenders.</description><pubDate>Mon, 27 Jul 2026 21:12:09 GMT</pubDate><category>Dysphoria</category><category>IoT Botnet</category><category>Blockchain C2</category><category>JackSkid</category><category>DDoS</category><category>Command and Control</category></item><item><title>SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly</title><link>https://runtimerebel.com/blog/sourtrade-malvertising-evasion-via-browser-side-bun-runtime-assembly</link><guid isPermaLink="true">https://runtimerebel.com/blog/sourtrade-malvertising-evasion-via-browser-side-bun-runtime-assembly</guid><description>The SourTrade malvertising operation bypasses security controls by using the victim&apos;s browser to assemble malicious Bun runtime executables in real-time.</description><pubDate>Sat, 25 Jul 2026 20:54:14 GMT</pubDate><category>SourTrade</category><category>Malvertising</category><category>Bun Runtime</category><category>Cryptocurrency Trading</category><category>Evasion Techniques</category></item><item><title>JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses</title><link>https://runtimerebel.com/blog/javascript-smuggling-in-memory-malware-assembly-evades-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/javascript-smuggling-in-memory-malware-assembly-evades-defenses</guid><description>Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.</description><pubDate>Sat, 25 Jul 2026 16:59:37 GMT</pubDate><category>Javascript Smuggling</category><category>Infostealer</category><category>Browser Security</category><category>Vidar</category><category>StealC</category></item><item><title>Dolphin X Malware: AI-Driven Target Prioritization &amp; Defense</title><link>https://runtimerebel.com/blog/dolphin-x-malware-ai-driven-target-prioritization-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/dolphin-x-malware-ai-driven-target-prioritization-defense</guid><description>Analysis of Dolphin X, a new RAT utilizing AI to profile and rank victims, enabling threat actors to prioritize high-value targets for data exfiltration and further…</description><pubDate>Fri, 24 Jul 2026 02:46:46 GMT</pubDate><category>DolphinX</category><category>RAT</category><category>AI</category><category>Targeting</category><category>Malware Analysis</category><category>Cyber Threat</category></item><item><title>Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware</title><link>https://runtimerebel.com/blog/bing-ads-promote-fake-claude-app-deliver-sectoprat-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/bing-ads-promote-fake-claude-app-deliver-sectoprat-malware</guid><description>A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.</description><pubDate>Thu, 23 Jul 2026 21:06:56 GMT</pubDate><category>Sectop RAT</category><category>Malvertising</category><category>Bing Ads</category><category>Claude AI</category><category>Information Stealer</category><category>Phishing</category></item><item><title>Notepad++ Plugin Abuse: LunchPoke Malware Establishes Persistence</title><link>https://runtimerebel.com/blog/notepad-plugin-abuse-lunchpoke-malware-establishes-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/notepad-plugin-abuse-lunchpoke-malware-establishes-persistence</guid><description>CERT-UA uncovers attacks where threat actors bundle malicious LunchPoke utility as a Notepad++ plugin for stealthy malware installation and persistence.</description><pubDate>Thu, 23 Jul 2026 17:27:43 GMT</pubDate><category>Notepad</category><category>LunchPoke</category><category>CERT UA</category><category>Malware</category><category>Persistence</category><category>Supply Chain Attack</category></item><item><title>Brazilian Banking Trojan Expansion into Portugal Targets Businesses</title><link>https://runtimerebel.com/blog/brazilian-banking-trojan-expansion-into-portugal-targets-businesses</link><guid isPermaLink="true">https://runtimerebel.com/blog/brazilian-banking-trojan-expansion-into-portugal-targets-businesses</guid><description>Portuguese businesses face increased risk from Brazilian banking trojans leveraging shared language for phishing and credential theft.</description><pubDate>Thu, 23 Jul 2026 10:27:20 GMT</pubDate><category>Banking Trojan</category><category>Portugal</category><category>Grandoreiro</category><category>Financial Crime</category><category>Phishing</category></item><item><title>msaRAT Malware Hijacks Browser Debugging for Stealthy C2 Traffic</title><link>https://runtimerebel.com/blog/msarat-malware-hijacks-browser-debugging-for-stealthy-c2-traffic</link><guid isPermaLink="true">https://runtimerebel.com/blog/msarat-malware-hijacks-browser-debugging-for-stealthy-c2-traffic</guid><description>Chaos ransomware operators deploy msaRAT, a new backdoor using Chromium-based browser debugging features to proxy C2 traffic and evade network security.</description><pubDate>Thu, 23 Jul 2026 10:25:27 GMT</pubDate><category>msaRAT</category><category>Chaos Ransomware</category><category>Chrome</category><category>Microsoft Edge</category><category>C2 Stealth</category><category>Remote Debugging</category></item><item><title>Ransomware Attack Freezes Japanese Food Supply Chain Operations</title><link>https://runtimerebel.com/blog/ransomware-attack-freezes-japanese-food-supply-chain-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransomware-attack-freezes-japanese-food-supply-chain-operations</guid><description>A ransomware attack on a Japanese food and logistics firm severely disrupted frozen food supply to thousands of clients, including KFC. Analyze the impact.</description><pubDate>Thu, 23 Jul 2026 02:52:03 GMT</pubDate><category>Ransomware</category><category>Supply Chain Attack</category><category>Food Sector</category><category>Japan</category><category>Logistics</category></item><item><title>Fake Bahrain Alert Apps Deploy Android Surveillance Malware</title><link>https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</guid><description>Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…</description><pubDate>Wed, 22 Jul 2026 21:12:30 GMT</pubDate><category>Android</category><category>Mobile Security</category><category>Spyware</category><category>Surveillance Malware</category><category>Fake Apps</category><category>Phishing</category><category>Social Engineering</category><category>Bahrain</category></item><item><title>FakeGit Campaign Leverages 7,600 GitHub Repos to Distribute SmartLoader, StealC</title><link>https://runtimerebel.com/blog/fakegit-campaign-leverages-7600-github-repos-to-distribute-smartloader-stealc</link><guid isPermaLink="true">https://runtimerebel.com/blog/fakegit-campaign-leverages-7600-github-repos-to-distribute-smartloader-stealc</guid><description>Analysis of the FakeGit campaign distributing SmartLoader and StealC malware via over 7,600 deceptive GitHub repositories, impacting millions of downloads.</description><pubDate>Wed, 22 Jul 2026 02:46:33 GMT</pubDate><category>FakeGit</category><category>SmartLoader</category><category>StealC</category><category>GitHub</category><category>Supply Chain Attack</category><category>Typosquatting</category><category>Malware Distribution</category></item><item><title>Anubis Ransomware Targets Fairlife, Threatens Data Leak</title><link>https://runtimerebel.com/blog/anubis-ransomware-targets-fairlife-threatens-data-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/anubis-ransomware-targets-fairlife-threatens-data-leak</guid><description>The Anubis ransomware gang claims responsibility for a cyberattack on Coca-Cola&apos;s Fairlife, threatening a data leak. Learn about their TTPs and mitigation.</description><pubDate>Tue, 21 Jul 2026 21:12:30 GMT</pubDate><category>Anubis Ransomware</category><category>Fairlife</category><category>Coca Cola</category><category>Data Exfiltration</category><category>Ransomware Group</category></item><item><title>ENCFORGE Ransomware Targets AI Systems via Langflow RCE</title><link>https://runtimerebel.com/blog/encforge-ransomware-targets-ai-systems-via-langflow-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/encforge-ransomware-targets-ai-systems-via-langflow-rce</guid><description>New ENCFORGE ransomware, attributed to JADEPUFFER, leverages a Langflow RCE vulnerability to encrypt AI model files, weights, and training data.</description><pubDate>Tue, 21 Jul 2026 10:39:45 GMT</pubDate><category>ENCFORGE</category><category>Ransomware</category><category>JADEPUFFER</category><category>Langflow</category><category>RCE</category><category>AI</category><category>Sysdig</category><category>Golang</category></item><item><title>FakeGit Campaign Exploits GitHub for SmartLoader Malware</title><link>https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</guid><description>Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.</description><pubDate>Mon, 20 Jul 2026 21:13:10 GMT</pubDate><category>FakeGit</category><category>SmartLoader</category><category>GitHub</category><category>Malware</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>Software Supply Chain</category></item><item><title>HollowGraph Malware Uses Microsoft Graph for Stealthy C2</title><link>https://runtimerebel.com/blog/hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2</guid><description>HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.</description><pubDate>Mon, 20 Jul 2026 18:05:43 GMT</pubDate><category>HollowGraph</category><category>Microsoft Graph</category><category>Microsoft 365</category><category>C2</category><category>Data Exfiltration</category><category>API Abuse</category></item><item><title>HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2</title><link>https://runtimerebel.com/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2</guid><description>HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.</description><pubDate>Mon, 20 Jul 2026 18:05:24 GMT</pubDate><category>HollowGraph</category><category>Microsoft 365</category><category>Microsoft Graph API</category><category>Espionage</category><category>C2</category><category>Data Exfiltration</category><category>Group IB</category></item><item><title>AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment</title><link>https://runtimerebel.com/blog/ai-assisted-phishing-leverages-webdav-for-infostealer-deployment</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-phishing-leverages-webdav-for-infostealer-deployment</guid><description>An exposed server revealed an AI-assisted phishing toolkit used in a WebDAV-based infostealer campaign targeting Windows users in Mexico. Learn detection and mitigation.</description><pubDate>Mon, 20 Jul 2026 18:05:04 GMT</pubDate><category>AI Assisted Phishing</category><category>WebDAV</category><category>Infostealer</category><category>Malware Toolkit</category><category>Mexico</category><category>Windows</category><category>Rapid7</category></item><item><title>ACR Stealer Campaign Targets Microsoft Enterprise Credentials</title><link>https://runtimerebel.com/blog/acr-stealer-campaign-targets-microsoft-enterprise-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/acr-stealer-campaign-targets-microsoft-enterprise-credentials</guid><description>Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.</description><pubDate>Sat, 18 Jul 2026 16:59:16 GMT</pubDate><category>ACR Stealer</category><category>Infostealer</category><category>Microsoft</category><category>Credential Theft</category></item><item><title>Fairlife Ransomware Attack Halts US Dairy Production</title><link>https://runtimerebel.com/blog/fairlife-ransomware-attack-halts-us-dairy-production</link><guid isPermaLink="true">https://runtimerebel.com/blog/fairlife-ransomware-attack-halts-us-dairy-production</guid><description>Coca-Cola&apos;s Fairlife dairy subsidiary suffered a ransomware attack, halting US production. Understand the operational impact and defense strategies.</description><pubDate>Fri, 17 Jul 2026 02:46:05 GMT</pubDate><category>Ransomware</category><category>Fairlife</category><category>Coca Cola</category><category>Food Beverage</category><category>Operational Technology</category><category>Supply Chain Attack</category></item><item><title>ClickLock macOS Malware: Password Theft via Forced Login Prompt</title><link>https://runtimerebel.com/blog/clicklock-macos-malware-password-theft-via-forced-login-prompt</link><guid isPermaLink="true">https://runtimerebel.com/blog/clicklock-macos-malware-password-theft-via-forced-login-prompt</guid><description>ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password. Learn how to identify and mitigate this…</description><pubDate>Fri, 17 Jul 2026 02:45:47 GMT</pubDate><category>macOS</category><category>ClickLock</category><category>Information Stealer</category><category>Password Theft</category><category>Social Engineering</category></item><item><title>OkoBot Framework: Multi-Payload Data &amp; Crypto Theft Attacks</title><link>https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</guid><description>The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data. Understand its impact and…</description><pubDate>Thu, 16 Jul 2026 21:02:27 GMT</pubDate><category>OkoBot</category><category>Malware</category><category>Infostealer</category><category>Cryptocurrency Theft</category><category>Credential Theft</category><category>Data Exfiltration</category></item><item><title>ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops</title><link>https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</link><guid isPermaLink="true">https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</guid><description>ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.</description><pubDate>Thu, 16 Jul 2026 14:03:10 GMT</pubDate><category>macOS</category><category>Infostealer</category><category>ClickLock</category><category>Social Engineering</category><category>Persistence</category></item><item><title>TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns</title><link>https://runtimerebel.com/blog/telepuz-malware-analyzing-modular-payloads-in-clickfix-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/telepuz-malware-analyzing-modular-payloads-in-clickfix-campaigns</guid><description>TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.</description><pubDate>Thu, 16 Jul 2026 14:00:24 GMT</pubDate><category>TELEPUZ</category><category>ClickFix</category><category>Social Engineering</category><category>Elastic Security Labs</category><category>Data Stealer</category></item><item><title>OkoBot Framework Injects Phishing Modules into Ledger and Trezor Apps</title><link>https://runtimerebel.com/blog/okobot-framework-injects-phishing-modules-into-ledger-and-trezor-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/okobot-framework-injects-phishing-modules-into-ledger-and-trezor-apps</guid><description>The OkoBot malware framework targets Windows users to steal hardware wallet seed phrases by injecting malicious pages directly into legitimate desktop apps.</description><pubDate>Wed, 15 Jul 2026 17:19:11 GMT</pubDate><category>OkoBot</category><category>Ledger</category><category>Trezor</category><category>Phishing</category><category>Hardware Wallet</category><category>Cryptocurrency</category></item><item><title>Malicious GitHub Repositories: Infostealer Distribution Threat</title><link>https://runtimerebel.com/blog/malicious-github-repositories-infostealer-distribution-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-github-repositories-infostealer-distribution-threat</guid><description>Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware. Learn to detect and mitigate this…</description><pubDate>Tue, 14 Jul 2026 21:03:07 GMT</pubDate><category>GitHub</category><category>Infostealer</category><category>Malware Distribution</category><category>Supply Chain Attack</category><category>Software Impersonation</category></item><item><title>LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows</title><link>https://runtimerebel.com/blog/labubarat-rust-based-rat-masquerades-as-nvidia-software-on-windows</link><guid isPermaLink="true">https://runtimerebel.com/blog/labubarat-rust-based-rat-masquerades-as-nvidia-software-on-windows</guid><description>Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.</description><pubDate>Tue, 14 Jul 2026 17:20:39 GMT</pubDate><category>LabubaRAT</category><category>Rust</category><category>NVIDIA</category><category>RAT</category><category>Windows</category><category>Remote Access Trojan</category></item><item><title>CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization</title><link>https://runtimerebel.com/blog/crashstealer-new-macos-info-stealer-bypasses-gatekeeper-via-notarization</link><guid isPermaLink="true">https://runtimerebel.com/blog/crashstealer-new-macos-info-stealer-bypasses-gatekeeper-via-notarization</guid><description>CrashStealer macOS malware leverages C++ and notarized droppers to evade security checks and exfiltrate validated credentials from compromised Apple devices.</description><pubDate>Mon, 13 Jul 2026 20:57:57 GMT</pubDate><category>CrashStealer</category><category>macOS Security</category><category>Information Stealer</category><category>Gatekeeper Bypass</category><category>Jamf Threat Labs</category></item><item><title>GigaWiper: Modular Implant Combines Backdoor &amp; Wiper Functions</title><link>https://runtimerebel.com/blog/gigawiper-modular-implant-combines-backdoor-wiper-functions</link><guid isPermaLink="true">https://runtimerebel.com/blog/gigawiper-modular-implant-combines-backdoor-wiper-functions</guid><description>Analysis of GigaWiper, a modular implant allowing threat actors to combine backdoor and wiper functionality for customizable destructive attacks and maximum impact.</description><pubDate>Mon, 13 Jul 2026 18:00:25 GMT</pubDate><category>GigaWiper</category><category>Wiper Malware</category><category>Backdoor</category><category>Modular Malware</category><category>Destructive Attacks</category></item><item><title>Analyzing Remcos RAT Delivery via Malicious LNK Files</title><link>https://runtimerebel.com/blog/analyzing-remcos-rat-delivery-via-malicious-lnk-files</link><guid isPermaLink="true">https://runtimerebel.com/blog/analyzing-remcos-rat-delivery-via-malicious-lnk-files</guid><description>Technical analysis of how threat actors use deceptive LNK files and obfuscated PowerShell to deliver Remcos RAT, including detection and mitigation strategies.</description><pubDate>Mon, 13 Jul 2026 02:56:21 GMT</pubDate><category>Remcos</category><category>LNK</category><category>PowerShell</category><category>Phishing</category></item><item><title>RedHook Android Malware: Abusing Wireless ADB for Local Shell Access</title><link>https://runtimerebel.com/blog/redhook-android-malware-abusing-wireless-adb-for-local-shell-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/redhook-android-malware-abusing-wireless-adb-for-local-shell-access</guid><description>RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.</description><pubDate>Sun, 12 Jul 2026 16:59:53 GMT</pubDate><category>RedHook</category><category>Android Security</category><category>ADB Exploitation</category><category>Mobile Threats</category><category>Wireless Debugging</category></item><item><title>MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2</title><link>https://runtimerebel.com/blog/modbeacon-rat-silver-fox-uses-grpc-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/modbeacon-rat-silver-fox-uses-grpc-for-stealthy-c2</guid><description>A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.</description><pubDate>Fri, 10 Jul 2026 14:30:03 GMT</pubDate><category>MODBEACON</category><category>RAT</category><category>Silver Fox</category><category>gRPC</category><category>C2</category><category>Rust</category><category>SEO Poisoning</category></item><item><title>GigaWiper Windows Backdoor Analysis: Disk Wiping &amp; Fake Ransomware</title><link>https://runtimerebel.com/blog/gigawiper-windows-backdoor-analysis-disk-wiping-fake-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/gigawiper-windows-backdoor-analysis-disk-wiping-fake-ransomware</guid><description>Runtime Rebel analyzes GigaWiper, a destructive Windows backdoor identified by Microsoft, bundling disk wiping, fake ransomware, and spyware capabilities. Understand its…</description><pubDate>Thu, 09 Jul 2026 21:32:34 GMT</pubDate><category>GigaWiper</category><category>Windows Backdoor</category><category>Disk Wiper</category><category>Fake Ransomware</category><category>Data Destruction</category><category>Microsoft</category></item><item><title>Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software</title><link>https://runtimerebel.com/blog/vidar-infostealer-malvertising-campaign-smbs-targeted-by-fake-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/vidar-infostealer-malvertising-campaign-smbs-targeted-by-fake-software</guid><description>A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…</description><pubDate>Wed, 08 Jul 2026 17:40:40 GMT</pubDate><category>Vidar Infostealer</category><category>Malvertising</category><category>SMBs</category><category>Cryptomining</category><category>Data Theft</category><category>Pirated Software</category></item><item><title>SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks</title><link>https://runtimerebel.com/blog/scmbanker-malware-analyzing-clickfix-lures-targeting-mexican-banks</link><guid isPermaLink="true">https://runtimerebel.com/blog/scmbanker-malware-analyzing-clickfix-lures-targeting-mexican-banks</guid><description>Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.</description><pubDate>Wed, 08 Jul 2026 14:14:47 GMT</pubDate><category>SCMBANKER</category><category>REF6045</category><category>Banking Trojan</category><category>Mexico</category><category>ClickFix</category><category>Phishing</category></item><item><title>RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis</title><link>https://runtimerebel.com/blog/redwing-maas-android-bank-fraud-via-telegram-rental-service-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/redwing-maas-android-bank-fraud-via-telegram-rental-service-analysis</guid><description>RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs. Learn to detect and…</description><pubDate>Tue, 07 Jul 2026 18:01:20 GMT</pubDate><category>RedWing</category><category>MaaS</category><category>Android</category><category>Banking Malware</category><category>Oblivion</category><category>Telegram</category><category>Mobile Security</category></item><item><title>BusySnake Infostealer Targets Critical Infrastructure: Armored Likho&apos;s TTPs</title><link>https://runtimerebel.com/blog/busysnake-infostealer-targets-critical-infrastructure-armored-likho-s-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/busysnake-infostealer-targets-critical-infrastructure-armored-likho-s-ttps</guid><description>BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.</description><pubDate>Tue, 07 Jul 2026 03:34:06 GMT</pubDate><category>BusySnake</category><category>Infostealer</category><category>Armored Likho</category><category>Critical Infrastructure</category><category>Government</category><category>Electrical Power</category><category>Russia</category><category>Brazil</category><category>Kazakhstan</category></item><item><title>Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot &amp; PowerShell</title><link>https://runtimerebel.com/blog/veil-drop-attacks-deploy-purelog-info-stealer-via-blogspot-powershell</link><guid isPermaLink="true">https://runtimerebel.com/blog/veil-drop-attacks-deploy-purelog-info-stealer-via-blogspot-powershell</guid><description>Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.</description><pubDate>Mon, 06 Jul 2026 21:40:18 GMT</pubDate><category>Veil Drop</category><category>PureLog</category><category>Information Stealer</category><category>Blogspot</category><category>PowerShell</category><category>Fileless Malware</category><category>Securonix</category></item><item><title>JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle</title><link>https://runtimerebel.com/blog/jadepuffer-ransomware-ai-agents-automate-the-full-attack-lifecycle</link><guid isPermaLink="true">https://runtimerebel.com/blog/jadepuffer-ransomware-ai-agents-automate-the-full-attack-lifecycle</guid><description>Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.</description><pubDate>Sat, 04 Jul 2026 17:09:08 GMT</pubDate><category>JADEPUFFER</category><category>AI Driven Attacks</category><category>LLM</category><category>Automated Exploitation</category><category>Ransomware</category></item><item><title>PamStealer: New macOS Malware Targets PAM for Password Exfiltration</title><link>https://runtimerebel.com/blog/pamstealer-new-macos-malware-targets-pam-for-password-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/pamstealer-new-macos-malware-targets-pam-for-password-exfiltration</guid><description>Jamf Threat Labs identifies PamStealer, a macOS malware using fake sites and AppleScript to steal login passwords through PAM exploitation.</description><pubDate>Fri, 03 Jul 2026 10:38:45 GMT</pubDate><category>PamStealer</category><category>macOS</category><category>Jamf Threat Labs</category><category>AppleScript</category><category>Credential Theft</category></item><item><title>ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse</title><link>https://runtimerebel.com/blog/toddycat-uses-umbrij-malware-to-target-gmail-via-google-api-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/toddycat-uses-umbrij-malware-to-target-gmail-via-google-api-abuse</guid><description>Runtime Rebel reports on ToddyCat&apos;s Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.</description><pubDate>Thu, 02 Jul 2026 14:06:01 GMT</pubDate><category>ToddyCat</category><category>Umbrij</category><category>Malware</category><category>Gmail</category><category>Google API</category><category>OAuth</category><category>Email Compromise</category><category>Kaspersky</category></item><item><title>Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users</title><link>https://runtimerebel.com/blog/ousaban-banking-trojan-phishing-lures-target-iberian-bank-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/ousaban-banking-trojan-phishing-lures-target-iberian-bank-users</guid><description>Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.</description><pubDate>Wed, 01 Jul 2026 16:53:05 GMT</pubDate><category>Ousaban</category><category>Banking Trojan</category><category>Phishing</category><category>Spain</category><category>Portugal</category><category>Windows</category><category>Financial Crime</category><category>Malware Analysis</category></item><item><title>Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets</title><link>https://runtimerebel.com/blog/silent-swap-crypto-clipper-fake-google-notes-ext-steals-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/silent-swap-crypto-clipper-fake-google-notes-ext-steals-wallets</guid><description>Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.</description><pubDate>Tue, 30 Jun 2026 16:48:05 GMT</pubDate><category>Silent Swap</category><category>Crypto Clipper</category><category>Cryptocurrency</category><category>Browser Extension</category><category>Malware</category><category>Financial Theft</category></item><item><title>Djinn Stealer Targets Cloud &amp; AI Credentials via SimpleHelp CVE-2026-48558</title><link>https://runtimerebel.com/blog/djinn-stealer-targets-cloud-ai-credentials-via-simplehelp-cve-2026-48558</link><guid isPermaLink="true">https://runtimerebel.com/blog/djinn-stealer-targets-cloud-ai-credentials-via-simplehelp-cve-2026-48558</guid><description>Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.</description><pubDate>Tue, 30 Jun 2026 09:19:57 GMT</pubDate><category>Djinn Stealer</category><category>CVE-2026-48558</category><category>SimpleHelp</category><category>Infostealer</category><category>Cloud Security</category><category>AI Credentials</category><category>Authentication Bypass</category></item><item><title>Microsoft Pulls 119 Malicious StegoAd Edge Extensions</title><link>https://runtimerebel.com/blog/microsoft-pulls-119-malicious-stegoad-edge-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-pulls-119-malicious-stegoad-edge-extensions</guid><description>Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.</description><pubDate>Mon, 29 Jun 2026 09:51:08 GMT</pubDate><category>Microsoft Edge</category><category>StegoAd</category><category>Browser Security</category><category>Steganography</category><category>Adware</category></item></channel></rss>