<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #APT</title><description>Cybersecurity articles tagged #APT on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Transparent Tribe Targets Afghan and Indian Organizations</title><link>https://runtimerebel.com/blog/transparent-tribe-targets-afghan-and-indian-organizations</link><guid isPermaLink="true">https://runtimerebel.com/blog/transparent-tribe-targets-afghan-and-indian-organizations</guid><description>Pakistan-linked Transparent Tribe updates its malware toolset to target Afghan organizations and government agencies in India.</description><pubDate>Thu, 20 Aug 2026 16:25:29 GMT</pubDate><category>Transparent Tribe</category><category>APT</category><category>Cyber Espionage</category><category>Malware</category></item><item><title>AI-Driven Cyberattack Targets APAC Government Agencies</title><link>https://runtimerebel.com/blog/ai-driven-cyberattack-targets-apac-government-agencies</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-cyberattack-targets-apac-government-agencies</guid><description>A China-linked actor reportedly deployed a near-autonomous AI framework to compromise government agencies in the APAC region, signaling a new threat landscape.</description><pubDate>Wed, 19 Aug 2026 08:27:30 GMT</pubDate><category>AI</category><category>Cyber Espionage</category><category>Nation State</category><category>APT</category><category>Asia Pacific</category></item><item><title>North Korea Attribution, Data Breaches Impact OnTrac &amp; UK Education</title><link>https://runtimerebel.com/blog/north-korea-attribution-data-breaches-impact-ontrac-uk-education</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korea-attribution-data-breaches-impact-ontrac-uk-education</guid><description>AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.</description><pubDate>Fri, 31 Jul 2026 17:43:11 GMT</pubDate><category>North Korea</category><category>APT</category><category>Data Breach</category><category>Ontrac</category><category>UK Department for Education</category><category>AWS</category></item><item><title>Google Unified Threat Actor Naming: TAG and Mandiant Convergence</title><link>https://runtimerebel.com/blog/google-unified-threat-actor-naming-tag-and-mandiant-convergence</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-unified-threat-actor-naming-tag-and-mandiant-convergence</guid><description>Google unifies threat actor naming across TAG and Mandiant to streamline attribution and improve intelligence sharing for security operations teams.</description><pubDate>Tue, 28 Jul 2026 10:39:08 GMT</pubDate><category>Google TAG</category><category>Mandiant</category><category>Threat Attribution</category><category>APT</category><category>Cybersecurity Standards</category></item><item><title>Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws</title><link>https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</guid><description>Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.</description><pubDate>Fri, 24 Jul 2026 17:42:24 GMT</pubDate><category>DolphinX</category><category>Emerald Sleet</category><category>Winter Vivern</category><category>UNC4841</category><category>Zimbra</category><category>Linux Kernel</category><category>Siemens ROX II</category><category>Industrial Control Systems</category><category>APT</category><category>Ransomware</category><category>LockBit</category></item><item><title>ViPNet Update Mechanism Abused in Russian Government Targeting</title><link>https://runtimerebel.com/blog/vipnet-update-mechanism-abused-in-russian-government-targeting</link><guid isPermaLink="true">https://runtimerebel.com/blog/vipnet-update-mechanism-abused-in-russian-government-targeting</guid><description>Threat actors are leveraging the ViPNet private networking suite&apos;s update mechanism to distribute malware to Russian government and financial entities.</description><pubDate>Sun, 19 Jul 2026 17:00:47 GMT</pubDate><category>ViPNet</category><category>Supply Chain Attack</category><category>Russian Government</category><category>InfoTeCS</category><category>APT</category></item><item><title>Advanced Persistent Threat Tracking: Intelligence for Detection</title><link>https://runtimerebel.com/blog/advanced-persistent-threat-tracking-intelligence-for-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/advanced-persistent-threat-tracking-intelligence-for-detection</guid><description>Understand the methodologies and critical role of real-time cyber intelligence in detecting and mitigating Advanced Persistent Threat (APT) group activities.</description><pubDate>Fri, 17 Jul 2026 17:15:19 GMT</pubDate><category>APT</category><category>Threat Intelligence</category><category>Cybersecurity</category><category>Detection</category><category>Threat Actors</category><category>Real Time Intelligence</category></item><item><title>AI-Enhanced Cyber Operations: Analyzing Iran&apos;s Asymmetric Playbook</title><link>https://runtimerebel.com/blog/ai-enhanced-cyber-operations-analyzing-iran-s-asymmetric-playbook</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-enhanced-cyber-operations-analyzing-iran-s-asymmetric-playbook</guid><description>Analysis of how Iranian state actors integrate artificial intelligence into cyber operations, influence campaigns, and domestic surveillance for asymmetric gains.</description><pubDate>Thu, 16 Jul 2026 14:10:25 GMT</pubDate><category>Iran</category><category>Artificial Intelligence</category><category>APT</category><category>Influence Operations</category><category>Cyber Warfare</category></item><item><title>Parallel APT Cyber Espionage Targets Balochistan Police</title><link>https://runtimerebel.com/blog/parallel-apt-cyber-espionage-targets-balochistan-police</link><guid isPermaLink="true">https://runtimerebel.com/blog/parallel-apt-cyber-espionage-targets-balochistan-police</guid><description>Analysis of parallel cyber espionage campaigns by China and India-linked APTs against Pakistan&apos;s Balochistan Police, detailed by SentinelOne.</description><pubDate>Fri, 10 Jul 2026 14:32:36 GMT</pubDate><category>China</category><category>India</category><category>Pakistan</category><category>Balochistan Police</category><category>APT</category><category>Cyber Espionage</category><category>SentinelOne</category><category>Nation State</category></item><item><title>Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance</title><link>https://runtimerebel.com/blog/iranian-nexus-tag-182-deploys-markirat-android-surveillance</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-nexus-tag-182-deploys-markirat-android-surveillance</guid><description>Runtime Rebel analyzes Iranian-nexus TAG-182&apos;s use of MarkiRAT malware. Disguised as fake VPN/media apps, it conducts cyber surveillance against domestic targets.</description><pubDate>Thu, 02 Jul 2026 07:41:52 GMT</pubDate><category>TAG 182</category><category>MarkiRAT</category><category>Iran</category><category>Cyber Surveillance</category><category>Android Malware</category><category>Mobile Threat</category><category>APT</category></item><item><title>Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks</title><link>https://runtimerebel.com/blog/mustang-panda-exploits-zoho-workdrive-for-c2-in-indian-govt-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/mustang-panda-exploits-zoho-workdrive-for-c2-in-indian-govt-attacks</guid><description>Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.</description><pubDate>Mon, 29 Jun 2026 17:06:24 GMT</pubDate><category>Mustang Panda</category><category>APT</category><category>Zoho WorkDrive</category><category>Indian Government</category><category>Espionage</category><category>C2</category><category>Cloud Security</category></item><item><title>Turla&apos;s STOCKSTAY Backdoor: Analysis of Campaigns &amp; WinRAR Exploit</title><link>https://runtimerebel.com/blog/turla-s-stockstay-backdoor-analysis-of-campaigns-winrar-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/turla-s-stockstay-backdoor-analysis-of-campaigns-winrar-exploit</guid><description>Google Threat Intelligence details STOCKSTAY, Turla&apos;s .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP &amp; CVE-2025-8088.</description><pubDate>Fri, 26 Jun 2026 09:21:08 GMT</pubDate><category>Turla</category><category>STOCKSTAY</category><category>KAZUAR</category><category>APT</category><category>Cyber Espionage</category><category>Ukraine</category><category>Government</category><category>Military</category><category>CVE-2025-8088</category><category>WinRAR</category><category>NET Malware</category><category>FSB</category></item><item><title>North Korean APT Targets Developers via Malicious Tooling</title><link>https://runtimerebel.com/blog/north-korean-apt-targets-developers-via-malicious-tooling</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-apt-targets-developers-via-malicious-tooling</guid><description>North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.</description><pubDate>Tue, 16 Jun 2026 01:12:25 GMT</pubDate><category>Contagious Interview</category><category>Famous Chollima</category><category>North Korea</category><category>APT</category><category>Phishing</category><category>Developer Tools</category><category>Supply Chain</category></item><item><title>UNC6508: Chinese Cyberespionage Targets North American Research</title><link>https://runtimerebel.com/blog/unc6508-chinese-cyberespionage-targets-north-american-research</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6508-chinese-cyberespionage-targets-north-american-research</guid><description>Google&apos;s Threat Intelligence Group tracks UNC6508, a Chinese cyberespionage group targeting North American medical, military, and AI research sectors.</description><pubDate>Mon, 15 Jun 2026 14:23:41 GMT</pubDate><category>UNC6508</category><category>Cyber Espionage</category><category>China</category><category>APT</category><category>North America</category><category>Medical Research</category><category>Military</category><category>AI Research</category></item><item><title>Chinese Hackers Hijack Auth Flow for Decade-Long Espionage</title><link>https://runtimerebel.com/blog/chinese-hackers-hijack-auth-flow-for-decade-long-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-hackers-hijack-auth-flow-for-decade-long-espionage</guid><description>Chinese state-sponsored hackers maintained long-term access to an isolated network by hijacking the authentication flow, enabling a decade of espionage.</description><pubDate>Sat, 13 Jun 2026 16:36:15 GMT</pubDate><category>Chinese Hackers</category><category>Authentication Bypass</category><category>Long Term Persistence</category><category>Espionage</category><category>Isolated Network</category><category>APT</category></item><item><title>Chinese and North Korean APT Activity Surges Across APAC Markets</title><link>https://runtimerebel.com/blog/chinese-and-north-korean-apt-activity-surges-across-apac-markets</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-and-north-korean-apt-activity-surges-across-apac-markets</guid><description>Chinese and North Korean threat groups are intensifying operations in Asia-Pacific, impacting regional economies and targeting financial institutions for profit.</description><pubDate>Thu, 11 Jun 2026 09:41:37 GMT</pubDate><category>Lazarus Group</category><category>Asia Pacific</category><category>Cyber Espionage</category><category>Financial Crime</category><category>APT</category></item><item><title>Chinese APT UNC5221 Deploys New Malware for M365 Persistence</title><link>https://runtimerebel.com/blog/chinese-apt-unc5221-deploys-new-malware-for-m365-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-apt-unc5221-deploys-new-malware-for-m365-persistence</guid><description>Chinese APT UNC5221 leverages new malware, Plenet and AgentPSD, alongside Brickstorm backdoor to maintain persistent access in compromised Microsoft 365 environments for…</description><pubDate>Fri, 05 Jun 2026 20:41:36 GMT</pubDate><category>UNC5221</category><category>Microsoft 365</category><category>BRICKSTORM</category><category>Plenet</category><category>AgentPSD</category><category>APT</category><category>Espionage</category></item><item><title>GreyVibe Threat Actor Leverages AI for Cyberattack Operations</title><link>https://runtimerebel.com/blog/greyvibe-threat-actor-leverages-ai-for-cyberattack-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/greyvibe-threat-actor-leverages-ai-for-cyberattack-operations</guid><description>Russia-linked GreyVibe threat actors are using AI tools like ChatGPT and Gemini to enhance cyberattacks, signaling a critical evolution in TTPs.</description><pubDate>Thu, 28 May 2026 20:53:51 GMT</pubDate><category>GREYVIBE</category><category>AI in Cyberattacks</category><category>Russia Linked</category><category>APT</category><category>ChatGPT</category><category>Gemini</category></item><item><title>Ghostwriter Targets Ukraine Government with Prometheus Phishing</title><link>https://runtimerebel.com/blog/ghostwriter-targets-ukraine-government-with-prometheus-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghostwriter-targets-ukraine-government-with-prometheus-phishing</guid><description>Belarus-aligned Ghostwriter (UAC-0057) targets Ukrainian government entities with Prometheus-themed phishing emails to deploy sophisticated malware.</description><pubDate>Fri, 22 May 2026 20:37:28 GMT</pubDate><category>Ghostwriter</category><category>UAC 0057</category><category>UNC1151</category><category>Ukraine</category><category>Government</category><category>Phishing</category><category>Prometheus</category><category>CERT UA</category><category>APT</category></item><item><title>Turla Updates Kazuar Backdoor with Modular P2P Botnet Capabilities</title><link>https://runtimerebel.com/blog/turla-updates-kazuar-backdoor-with-modular-p2p-botnet-capabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/turla-updates-kazuar-backdoor-with-modular-p2p-botnet-capabilities</guid><description>Russian threat actor Turla (Secret Blizzard) has upgraded its Kazuar backdoor with peer-to-peer botnet functionality and modular architecture for stealth.</description><pubDate>Sat, 16 May 2026 16:23:51 GMT</pubDate><category>Turla</category><category>Secret Blizzard</category><category>KAZUAR</category><category>P2P Botnet</category><category>NET Backdoor</category><category>APT</category><category>Russian Espionage</category></item><item><title>FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing</title><link>https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</guid><description>Belarussian APT &apos;FrostyNeighbor&apos; is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…</description><pubDate>Thu, 14 May 2026 20:38:13 GMT</pubDate><category>FrostyNeighbor</category><category>APT</category><category>Belarus</category><category>Poland</category><category>Ukraine</category><category>Espionage</category><category>Spear Phishing</category><category>Government</category><category>Nation State</category></item><item><title>Ghostwriter Targets Ukraine with Geofenced PDF Phishing &amp; Cobalt Strike</title><link>https://runtimerebel.com/blog/ghostwriter-targets-ukraine-with-geofenced-pdf-phishing-cobalt-strike</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghostwriter-targets-ukraine-with-geofenced-pdf-phishing-cobalt-strike</guid><description>Ghostwriter (UAC-0057) leverages geofenced PDF phishing to deliver Cobalt Strike against Ukrainian government entities, combining espionage and influence.</description><pubDate>Thu, 14 May 2026 16:45:40 GMT</pubDate><category>Ghostwriter</category><category>UAC 0057</category><category>Ukraine</category><category>Phishing</category><category>Cobalt Strike</category><category>APT</category></item><item><title>MuddyWater Targets South Korean Electronics Maker in Espionage Campaign</title><link>https://runtimerebel.com/blog/muddywater-targets-south-korean-electronics-maker-in-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-targets-south-korean-electronics-maker-in-espionage-campaign</guid><description>Iran-linked MuddyWater (Seedworm) group launched a cyber-espionage campaign against a major South Korean electronics maker and other global entities.</description><pubDate>Thu, 14 May 2026 00:55:56 GMT</pubDate><category>MuddyWater</category><category>Seedworm</category><category>Static Kitten</category><category>Iran</category><category>Cyber Espionage</category><category>South Korea</category><category>Electronics Maker</category><category>APT</category></item><item><title>MuddyWater Exploits Microsoft Teams for False Flag Ransomware</title><link>https://runtimerebel.com/blog/muddywater-exploits-microsoft-teams-for-false-flag-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-exploits-microsoft-teams-for-false-flag-ransomware</guid><description>Iranian APT MuddyWater is leveraging Microsoft Teams social engineering to deploy false flag ransomware, obscuring state-sponsored espionage activities.</description><pubDate>Wed, 06 May 2026 16:38:58 GMT</pubDate><category>MuddyWater</category><category>Microsoft Teams</category><category>Ransomware</category><category>APT</category><category>Social Engineering</category></item><item><title>China-Linked UAT-8302 Targets Governments with Custom APT Malware</title><link>https://runtimerebel.com/blog/china-linked-uat-8302-targets-governments-with-custom-apt-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-uat-8302-targets-governments-with-custom-apt-malware</guid><description>UAT-8302, a China-linked threat group, targets government entities in South America and SE Europe using custom malware and shared APT toolsets.</description><pubDate>Tue, 05 May 2026 16:39:00 GMT</pubDate><category>UAT 8302</category><category>China</category><category>APT</category><category>Cisco Talos</category><category>Cyber Espionage</category></item><item><title>Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia</title><link>https://runtimerebel.com/blog/silver-fox-apt-tax-themed-phishing-delivers-abcdoor-to-india-russia</link><guid isPermaLink="true">https://runtimerebel.com/blog/silver-fox-apt-tax-themed-phishing-delivers-abcdoor-to-india-russia</guid><description>China-backed Silver Fox APT targets organizations in India and Russia with over 1,600 tax-themed phishing messages to deploy ABCDoor backdoor and ValleyRAT.</description><pubDate>Mon, 04 May 2026 16:46:54 GMT</pubDate><category>Silver Fox</category><category>ABCSDoor</category><category>ValleyRAT</category><category>Phishing</category><category>India</category><category>Russia</category><category>APT</category><category>Backdoor</category><category>Tax Themed Attacks</category></item><item><title>20 Years of Threat Intel: Analyzing Adversarial Evolution Since 2006</title><link>https://runtimerebel.com/blog/20-years-of-threat-intel-analyzing-adversarial-evolution-since-2006</link><guid isPermaLink="true">https://runtimerebel.com/blog/20-years-of-threat-intel-analyzing-adversarial-evolution-since-2006</guid><description>Historical analysis of cybersecurity threat evolution over two decades, focusing on the transition from simple exploits to complex APT campaigns.</description><pubDate>Fri, 01 May 2026 12:30:26 GMT</pubDate><category>Threat Intelligence</category><category>Cyber History</category><category>APT</category><category>Ransomware Evolution</category></item><item><title>Lazarus Group&apos;s $2B+ Crypto Theft: Defending Against Supply Chain Attacks</title><link>https://runtimerebel.com/blog/lazarus-group-s-2b-crypto-theft-defending-against-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/lazarus-group-s-2b-crypto-theft-defending-against-supply-chain-attacks</guid><description>An analysis of Lazarus Group&apos;s persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.</description><pubDate>Tue, 28 Apr 2026 16:47:53 GMT</pubDate><category>Lazarus Group</category><category>DPRK</category><category>Cryptocurrency Theft</category><category>Supply Chain Attack</category><category>Financial Cybercrime</category><category>APT</category></item><item><title>Alleged Silk Typhoon Hacker Extradited: Cyberespionage Threat</title><link>https://runtimerebel.com/blog/alleged-silk-typhoon-hacker-extradited-cyberespionage-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/alleged-silk-typhoon-hacker-extradited-cyberespionage-threat</guid><description>An alleged Silk Typhoon hacker, associated with Chinese intelligence, has been extradited to the US, highlighting persistent nation-state cyberespionage threats.</description><pubDate>Mon, 27 Apr 2026 20:30:07 GMT</pubDate><category>Silk Typhoon</category><category>Volt Typhoon</category><category>Cyber Espionage</category><category>Nation State</category><category>China</category><category>Extradition</category><category>APT</category></item><item><title>Chinese State-Backed Actors Industrialize Botnets for Covert Ops</title><link>https://runtimerebel.com/blog/chinese-state-backed-actors-industrialize-botnets-for-covert-ops</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-state-backed-actors-industrialize-botnets-for-covert-ops</guid><description>Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.</description><pubDate>Fri, 24 Apr 2026 00:47:01 GMT</pubDate><category>China</category><category>State Backed</category><category>Botnet</category><category>APT</category><category>Cyber Espionage</category><category>Industrialized Botnets</category></item><item><title>FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower &amp; Secure Firewall</title><link>https://runtimerebel.com/blog/firestarter-backdoor-persistent-threat-to-cisco-firepower-secure-firewall</link><guid isPermaLink="true">https://runtimerebel.com/blog/firestarter-backdoor-persistent-threat-to-cisco-firepower-secure-firewall</guid><description>CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.</description><pubDate>Thu, 23 Apr 2026 16:44:19 GMT</pubDate><category>FIRESTARTER</category><category>Cisco Firepower</category><category>Cisco Secure Firewall</category><category>Cisco ASA</category><category>Backdoor</category><category>APT</category><category>CVE-2025-20333</category><category>CVE-2025-20362</category><category>LINE VIPER</category><category>Persistence</category></item><item><title>GopherWhisper APT Abuses Outlook and Slack for Stealthy C2</title><link>https://runtimerebel.com/blog/gopherwhisper-apt-abuses-outlook-and-slack-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/gopherwhisper-apt-abuses-outlook-and-slack-for-stealthy-c2</guid><description>Newly discovered GopherWhisper APT group uses a Go-based toolkit and legitimate SaaS platforms like Slack and Outlook to conduct espionage against governments.</description><pubDate>Thu, 23 Apr 2026 12:29:29 GMT</pubDate><category>GopherWhisper</category><category>APT</category><category>C2</category><category>Outlook</category><category>Slack</category><category>Discord</category><category>Go Malware</category></item><item><title>Sapphire Sleet&apos;s ClickFix: North Korea Targets macOS Users</title><link>https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</guid><description>North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.</description><pubDate>Thu, 16 Apr 2026 20:22:49 GMT</pubDate><category>Sapphire Sleet</category><category>ClickFix</category><category>macOS</category><category>North Korea</category><category>Phishing</category><category>Data Theft</category><category>APT</category></item><item><title>Iran Geopolitical Tensions: Cyber Implications &amp; Preparedness</title><link>https://runtimerebel.com/blog/iran-geopolitical-tensions-cyber-implications-preparedness</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-geopolitical-tensions-cyber-implications-preparedness</guid><description>Examine the potential cybersecurity implications of escalating geopolitical tensions involving Iran, focusing on nation-state TTPs and organizational preparedness…</description><pubDate>Tue, 14 Apr 2026 20:28:00 GMT</pubDate><category>Iran</category><category>Nation State</category><category>Geopolitical Threat</category><category>Cyber Warfare</category><category>Critical Infrastructure</category><category>APT</category><category>Threat Intelligence</category></item><item><title>UAT-10362 Targets Taiwanese NGOs with LucidRook Malware</title><link>https://runtimerebel.com/blog/uat-10362-targets-taiwanese-ngos-with-lucidrook-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-10362-targets-taiwanese-ngos-with-lucidrook-malware</guid><description>Runtime Rebel analyzes UAT-10362&apos;s sophisticated spear-phishing campaigns deploying new Lua-based LucidRook malware against Taiwanese NGOs and universities.</description><pubDate>Fri, 10 Apr 2026 00:40:34 GMT</pubDate><category>UAT 10362</category><category>LucidRook</category><category>Taiwan</category><category>NGO</category><category>Spear Phishing</category><category>Lua Malware</category><category>Rust Malware</category><category>APT</category></item><item><title>TA416 Targets European Govts with PlugX &amp; OAuth Phishing</title><link>https://runtimerebel.com/blog/ta416-targets-european-govts-with-plugx-oauth-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/ta416-targets-european-govts-with-plugx-oauth-phishing</guid><description>China-linked TA416 has resumed targeting European government and diplomatic entities since mid-2025 using PlugX and OAuth-based phishing attacks.</description><pubDate>Fri, 03 Apr 2026 20:13:24 GMT</pubDate><category>TA416</category><category>DarkPeony</category><category>PlugX</category><category>Oauth Phishing</category><category>APT</category><category>European Governments</category><category>China Linked</category></item><item><title>Quantum Geopolitics: Cyber Threats in an Era of Iran Conflict</title><link>https://runtimerebel.com/blog/quantum-geopolitics-cyber-threats-in-an-era-of-iran-conflict</link><guid isPermaLink="true">https://runtimerebel.com/blog/quantum-geopolitics-cyber-threats-in-an-era-of-iran-conflict</guid><description>Analyze how the shift toward quantum geopolitics and Iranian proxy conflicts impact global cyber stability and critical infrastructure protection.</description><pubDate>Thu, 02 Apr 2026 08:35:45 GMT</pubDate><category>Iran</category><category>Geopolitics</category><category>APT</category><category>Middle East</category><category>Critical Infrastructure</category></item><item><title>Iranian Hackers Target Kash Patel: US Offers $10M Bounty</title><link>https://runtimerebel.com/blog/iranian-hackers-target-kash-patel-us-offers-10m-bounty</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-hackers-target-kash-patel-us-offers-10m-bounty</guid><description>The FBI confirms Iranian state-sponsored hackers compromised Kash Patel’s personal email, leading the U.S. to offer a $10M reward for information.</description><pubDate>Mon, 30 Mar 2026 08:42:33 GMT</pubDate><category>Iran</category><category>FBI</category><category>Kash Patel</category><category>Election Interference</category><category>State Sponsored</category><category>APT</category></item><item><title>China-Linked APT Clusters Target SE Asian Government via HIUPAN</title><link>https://runtimerebel.com/blog/china-linked-apt-clusters-target-se-asian-government-via-hiupan</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-apt-clusters-target-se-asian-government-via-hiupan</guid><description>Three China-linked threat clusters targeted a Southeast Asian government in 2025 using HIUPAN, PUBLOAD, and EggStremeFuel malware in a complex espionage operation.</description><pubDate>Mon, 30 Mar 2026 08:39:27 GMT</pubDate><category>China</category><category>Hiupan</category><category>Pubload</category><category>Eggstremefuel</category><category>Southeast Asia</category><category>APT</category><category>Malware</category></item><item><title>Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos</title><link>https://runtimerebel.com/blog/red-menshen-apt-deploys-upgraded-bpfdoor-backdoor-against-telcos</link><guid isPermaLink="true">https://runtimerebel.com/blog/red-menshen-apt-deploys-upgraded-bpfdoor-backdoor-against-telcos</guid><description>Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.</description><pubDate>Fri, 27 Mar 2026 20:16:14 GMT</pubDate><category>Red Menshen</category><category>BPFdoor</category><category>APT</category><category>Telecommunications</category><category>China</category><category>Backdoor</category><category>Espionage</category></item><item><title>Red Menshen BPFDoor Implants Target Telecom Networks for Espionage</title><link>https://runtimerebel.com/blog/red-menshen-bpfdoor-implants-target-telecom-networks-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/red-menshen-bpfdoor-implants-target-telecom-networks-for-espionage</guid><description>Analysis of China-linked Red Menshen&apos;s long-term campaign using stealthy BPFDoor implants within telecom networks to conduct espionage against government entities.</description><pubDate>Thu, 26 Mar 2026 20:14:16 GMT</pubDate><category>Red Menshen</category><category>Earth Bluecrow</category><category>BPFdoor</category><category>Telecom</category><category>Espionage</category><category>China Nexus</category><category>APT</category></item><item><title>Russian Intelligence Phishing Targets Signal and WhatsApp Users</title><link>https://runtimerebel.com/blog/russian-intelligence-phishing-targets-signal-and-whatsapp-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-intelligence-phishing-targets-signal-and-whatsapp-users</guid><description>The FBI warns of sophisticated phishing campaigns by Russian intelligence targeting Signal and WhatsApp users to harvest credentials and bypass encryption.</description><pubDate>Sat, 21 Mar 2026 00:33:28 GMT</pubDate><category>Signal</category><category>WhatsApp</category><category>Phishing</category><category>Russian Intelligence</category><category>APT</category><category>Social Engineering</category></item><item><title>Bitrefill Attributes Cyberattack to North Korean Lazarus Group</title><link>https://runtimerebel.com/blog/bitrefill-attributes-cyberattack-to-north-korean-lazarus-group</link><guid isPermaLink="true">https://runtimerebel.com/blog/bitrefill-attributes-cyberattack-to-north-korean-lazarus-group</guid><description>Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.</description><pubDate>Thu, 19 Mar 2026 20:16:23 GMT</pubDate><category>Lazarus Group</category><category>BlueNoroff</category><category>Bitrefill</category><category>Cryptocurrency</category><category>APT</category><category>North Korea</category></item><item><title>SideWinder APT Expands Southeast Asia Espionage Campaign</title><link>https://runtimerebel.com/blog/sidewinder-apt-expands-southeast-asia-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/sidewinder-apt-expands-southeast-asia-espionage-campaign</guid><description>SideWinder APT targets government and telecom sectors in Southeast Asia using spear-phishing and rotating infrastructure for persistent espionage operations.</description><pubDate>Wed, 18 Mar 2026 16:31:14 GMT</pubDate><category>SideWinder</category><category>APT</category><category>Southeast Asia</category><category>Spear Phishing</category><category>CVE-2017-11882</category></item><item><title>Konni Group Deploys EndRAT via Phishing and KakaoTalk Hijacking</title><link>https://runtimerebel.com/blog/konni-group-deploys-endrat-via-phishing-and-kakaotalk-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/konni-group-deploys-endrat-via-phishing-and-kakaotalk-hijacking</guid><description>North Korean threat actor Konni leverages spear-phishing and KakaoTalk desktop exploitation to distribute EndRAT malware and facilitate lateral movement.</description><pubDate>Tue, 17 Mar 2026 12:30:14 GMT</pubDate><category>Konni</category><category>Endrat</category><category>Kakaotalk</category><category>APT</category><category>Spear Phishing</category></item><item><title>Poland’s Nuclear Center Targeted in Suspected Iranian Cyberattack</title><link>https://runtimerebel.com/blog/polands-nuclear-center-targeted-in-suspected-iranian-cyberattack</link><guid isPermaLink="true">https://runtimerebel.com/blog/polands-nuclear-center-targeted-in-suspected-iranian-cyberattack</guid><description>Polish officials investigate a cyberattack at the NCBJ nuclear center. Initial evidence points to Iran, but investigators warn of potential false flag tactics.</description><pubDate>Mon, 16 Mar 2026 12:25:26 GMT</pubDate><category>NCBJ</category><category>Poland</category><category>Critical Infrastructure</category><category>Iran</category><category>APT</category></item><item><title>Iranian MOIS Collusion with Cybercriminals: Evolving Hybrid Threat</title><link>https://runtimerebel.com/blog/iranian-mois-collusion-with-cybercriminals-evolving-hybrid-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-mois-collusion-with-cybercriminals-evolving-hybrid-threat</guid><description>Iranian state-sponsored APTs, linked to MOIS, are now directly collaborating with cybercriminal organizations, escalating hybrid cyber operations. Defenders must adapt.</description><pubDate>Fri, 13 Mar 2026 00:35:19 GMT</pubDate><category>Iran</category><category>MOIS</category><category>Nation State</category><category>Cybercrime</category><category>APT</category><category>Hybrid Warfare</category><category>Threat Intelligence</category></item><item><title>TfL Data Breach and Avira Security Flaws: Weekly Threat Briefing</title><link>https://runtimerebel.com/blog/tfl-data-breach-and-avira-security-flaws-weekly-threat-briefing</link><guid isPermaLink="true">https://runtimerebel.com/blog/tfl-data-breach-and-avira-security-flaws-weekly-threat-briefing</guid><description>Analysis of the Transport for London breach affecting 10 million users, Avira antivirus security flaws, and North Korean cyber actor attribution.</description><pubDate>Fri, 06 Mar 2026 16:21:41 GMT</pubDate><category>Data Breach</category><category>Avira Antivirus</category><category>Lazarus Group</category><category>Tfl Breach</category><category>APT</category></item><item><title>Coruna Exploit Kit: iOS 13-17.2.1 Targeted by Multiple APTs</title><link>https://runtimerebel.com/blog/coruna-exploit-kit-ios-13-17-2-1-targeted-by-multiple-apts</link><guid isPermaLink="true">https://runtimerebel.com/blog/coruna-exploit-kit-ios-13-17-2-1-targeted-by-multiple-apts</guid><description>Google Threat Intelligence Group details Coruna, a powerful iOS exploit kit targeting versions 13.0 to 17.2.1, used by commercial vendors and nation-state actors for…</description><pubDate>Tue, 03 Mar 2026 16:26:20 GMT</pubDate><category>Coruna</category><category>iOS</category><category>Exploit Kit</category><category>WebKit RCE</category><category>APT</category><category>UNC6353</category><category>UNC6691</category><category>Commercial Surveillance</category><category>Zero-Day</category><category>CVE-2024-23222</category><category>CVE-2022-48503</category><category>CVE-2023-43000</category><category>CVE-2021-30952</category><category>CVE-2023-32409</category><category>CVE-2020-27932</category><category>CVE-2020-27950</category><category>CVE-2023-32434</category><category>CVE-2023-41974</category><category>CVE-2023-38606</category><category>CVE-2024-23225</category><category>CVE-2024-23296</category></item><item><title>Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches</title><link>https://runtimerebel.com/blog/google-disrupts-unc2814-gridtide-infrastructure-after-53-breaches</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-disrupts-unc2814-gridtide-infrastructure-after-53-breaches</guid><description>Google disrupts infrastructure of China-nexus threat actor UNC2814 (GRIDTIDE) after 53 breaches across 42 countries targeting government and telecom sectors.</description><pubDate>Wed, 25 Feb 2026 20:15:13 GMT</pubDate><category>UNC2814</category><category>GRIDTIDE</category><category>China Nexus</category><category>APT</category><category>Telecommunications</category><category>Espionage</category></item></channel></rss>