<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #APT28</title><description>Cybersecurity articles tagged #APT28 on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Leaked Russian Cyber-Ops Training Exposes Institutional Pathways</title><link>https://runtimerebel.com/blog/leaked-russian-cyber-ops-training-exposes-institutional-pathways</link><guid isPermaLink="true">https://runtimerebel.com/blog/leaked-russian-cyber-ops-training-exposes-institutional-pathways</guid><description>Leaked materials reveal Russia&apos;s institutional system for generating cyber capabilities, linking university recruitment to GRU and Sandworm units for diverse operations.</description><pubDate>Tue, 01 Sep 2026 19:02:45 GMT</pubDate><category>GRU</category><category>Sandworm</category><category>Russia</category><category>Cyber Warfare</category><category>APT28</category></item><item><title>APT28&apos;s HOOKEDGE Backdoor Targets European Diplomacy</title><link>https://runtimerebel.com/blog/apt28-s-hookedge-backdoor-targets-european-diplomacy</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-s-hookedge-backdoor-targets-european-diplomacy</guid><description>Russian state-sponsored BlueDelta (APT28) leverages HOOKEDGE backdoor via macro-enabled documents to target European government and diplomatic entities.</description><pubDate>Tue, 01 Sep 2026 02:51:27 GMT</pubDate><category>Spear Phishing</category><category>BlueDelta</category><category>APT28</category><category>HOOKEDGE</category><category>HEADLACE</category></item><item><title>Microsoft OWA Exploit: Russian Hackers Bypass Credential Rotations</title><link>https://runtimerebel.com/blog/microsoft-owa-exploit-russian-hackers-bypass-credential-rotations</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-owa-exploit-russian-hackers-bypass-credential-rotations</guid><description>Russian threat actors exploit a Microsoft Outlook Web Access (OWA) flaw to maintain persistent mailbox access even after passwords are changed or rotated.</description><pubDate>Thu, 30 Jul 2026 10:25:52 GMT</pubDate><category>APT28</category><category>Microsoft OWA</category><category>Credential Rotation Bypass</category><category>State Sponsored</category></item><item><title>APT28 Exploits Exchange OWA Zero-Day to Deploy OWAReaper Backdoor</title><link>https://runtimerebel.com/blog/apt28-exploits-exchange-owa-zero-day-to-deploy-owareaper-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-exploits-exchange-owa-zero-day-to-deploy-owareaper-backdoor</guid><description>Russian APT28 hackers exploit an Exchange OWA zero-day to deploy the OWAReaper backdoor, gaining persistent access to high-value government mailboxes.</description><pubDate>Thu, 30 Jul 2026 02:30:39 GMT</pubDate><category>APT28</category><category>CVE-2024-43451</category><category>OWAReaper</category><category>Microsoft Exchange</category></item><item><title>Russian APT Exploits Zimbra Zero-Day to Exfiltrate Mail and 2FA Codes</title><link>https://runtimerebel.com/blog/russian-apt-exploits-zimbra-zero-day-to-exfiltrate-mail-and-2fa-codes</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-apt-exploits-zimbra-zero-day-to-exfiltrate-mail-and-2fa-codes</guid><description>Russian state-supported actors leveraged a Zimbra Zero-Day to steal 90 days of email history and bypass security by exfiltrating 2FA recovery codes.</description><pubDate>Thu, 23 Jul 2026 21:06:08 GMT</pubDate><category>Zimbra</category><category>Russian Espionage</category><category>APT28</category><category>Zero-Day</category><category>Email Security</category></item><item><title>Zimbra Zero-Click Exploitation by Russian APT for Email Theft</title><link>https://runtimerebel.com/blog/zimbra-zero-click-exploitation-by-russian-apt-for-email-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-zero-click-exploitation-by-russian-apt-for-email-theft</guid><description>CISA warns of Russian APT Laundry Bear (Void Blizzard) exploiting a patched Zimbra zero-click flaw combined with phishing to compromise email servers for data…</description><pubDate>Thu, 23 Jul 2026 17:27:19 GMT</pubDate><category>Laundry Bear</category><category>Void Blizzard</category><category>APT28</category><category>Zimbra Collaboration</category><category>Zero Click</category><category>Email Theft</category><category>Phishing</category><category>Russian APT</category></item><item><title>UK and EU Sanction Russian APTs Over Critical Infrastructure Attacks</title><link>https://runtimerebel.com/blog/uk-and-eu-sanction-russian-apts-over-critical-infrastructure-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-and-eu-sanction-russian-apts-over-critical-infrastructure-attacks</guid><description>Recent UK and EU sanctions target Russian intelligence services following persistent cyber operations against government entities and critical infrastructure.</description><pubDate>Tue, 14 Jul 2026 02:36:59 GMT</pubDate><category>APT28</category><category>APT29</category><category>Russian Cyberattacks</category><category>Critical Infrastructure</category><category>Sanctions</category></item><item><title>EU Sanctions Russian Intel Officers for APT28 Cyber Operations</title><link>https://runtimerebel.com/blog/eu-sanctions-russian-intel-officers-for-apt28-cyber-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/eu-sanctions-russian-intel-officers-for-apt28-cyber-operations</guid><description>The EU imposes sanctions on Russian GRU officers linked to APT28 for long-term cyber espionage and sabotage targeting government and infrastructure.</description><pubDate>Mon, 13 Jul 2026 11:22:06 GMT</pubDate><category>APT28</category><category>GRU</category><category>EU Sanctions</category><category>Cyber Espionage</category><category>Critical Infrastructure</category></item><item><title>Russian APTs Target Critical Infrastructure via Edge Device Exploits</title><link>https://runtimerebel.com/blog/russian-apts-target-critical-infrastructure-via-edge-device-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-apts-target-critical-infrastructure-via-edge-device-exploits</guid><description>US and allies warn of Russian state-sponsored actors targeting edge devices to infiltrate critical infrastructure. Learn how to mitigate these threats.</description><pubDate>Mon, 13 Jul 2026 11:21:02 GMT</pubDate><category>APT28</category><category>Sandworm</category><category>Cisco</category><category>Critical Infrastructure</category><category>Edge Security</category></item><item><title>CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw</title><link>https://runtimerebel.com/blog/cve-2023-38831-russian-apts-target-ukraine-via-winrar-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-38831-russian-apts-target-ukraine-via-winrar-flaw</guid><description>Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.</description><pubDate>Tue, 09 Jun 2026 17:01:57 GMT</pubDate><category>CVE-2023-38831</category><category>WinRAR</category><category>APT28</category><category>Sandworm</category><category>Ukraine</category></item><item><title>APT28 Exploits Incomplete Windows Patch: Zero-Click Attacks Persist</title><link>https://runtimerebel.com/blog/apt28-exploits-incomplete-windows-patch-zero-click-attacks-persist</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-exploits-incomplete-windows-patch-zero-click-attacks-persist</guid><description>An incomplete Windows patch leaves systems vulnerable to zero-click attacks. Russia-linked APT28 exploited this against Ukraine and EU. Learn how to defend.</description><pubDate>Mon, 27 Apr 2026 16:40:47 GMT</pubDate><category>Windows</category><category>Zero Click</category><category>APT28</category><category>Patch Bypass</category><category>Vulnerability</category><category>Microsoft</category><category>Cyber Warfare</category></item><item><title>APT28 Analysis: Mitigation Strategies Against Fancy Bear Campaigns</title><link>https://runtimerebel.com/blog/apt28-analysis-mitigation-strategies-against-fancy-bear-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-analysis-mitigation-strategies-against-fancy-bear-campaigns</guid><description>A technical analysis of APT28&apos;s global operations, highlighting the necessity of Zero Trust and rapid patching to counter Fancy Bear threat activity.</description><pubDate>Fri, 10 Apr 2026 08:40:01 GMT</pubDate><category>APT28</category><category>Fancy Bear</category><category>Russia</category><category>Nation State</category><category>Zero Trust</category></item><item><title>APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers</title><link>https://runtimerebel.com/blog/apt28-forest-blizzard-dns-manipulation-targets-soho-routers</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-forest-blizzard-dns-manipulation-targets-soho-routers</guid><description>Russian APT28, or Forest Blizzard, is conducting malwareless cyber espionage by manipulating DNS settings on vulnerable SOHO routers to steal credentials from global…</description><pubDate>Thu, 09 Apr 2026 04:53:01 GMT</pubDate><category>APT28</category><category>Forest Blizzard</category><category>SOHO Routers</category><category>DNS Manipulation</category><category>Credential Theft</category><category>Cyber Espionage</category><category>Nation State</category></item><item><title>APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware</title><link>https://runtimerebel.com/blog/apt28-targets-ukraine-and-nato-allies-with-new-prismex-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-targets-ukraine-and-nato-allies-with-new-prismex-malware</guid><description>APT28 (Forest Blizzard) deploys the undocumented PRISMEX malware suite against Ukraine and NATO, utilizing COM hijacking and cloud-based C2 infrastructure.</description><pubDate>Wed, 08 Apr 2026 16:31:54 GMT</pubDate><category>APT28</category><category>PRISMEX</category><category>Forest Blizzard</category><category>Ukraine</category><category>NATO</category><category>COM Hijacking</category></item><item><title>APT28 Exploits MikroTik &amp; TP-Link Routers in DNS Hijacking</title><link>https://runtimerebel.com/blog/apt28-exploits-mikrotik-tp-link-routers-in-dns-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-exploits-mikrotik-tp-link-routers-in-dns-hijacking</guid><description>Russian state-linked APT28 (Forest Blizzard) is compromising insecure SOHO routers globally, employing DNS hijacking for cyber espionage since May 2025.</description><pubDate>Tue, 07 Apr 2026 20:18:04 GMT</pubDate><category>APT28</category><category>Forest Blizzard</category><category>SOHO Routers</category><category>MikroTik</category><category>TP Link</category><category>DNS Hijacking</category><category>Cyber Espionage</category></item><item><title>APT28 FrostArmada DNS Hijack Campaign Steals Microsoft 365 Logins</title><link>https://runtimerebel.com/blog/apt28-frostarmada-dns-hijack-campaign-steals-microsoft-365-logins</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-frostarmada-dns-hijack-campaign-steals-microsoft-365-logins</guid><description>Authorities disrupt APT28&apos;s FrostArmada campaign, which used DNS hijacking of MikroTik and TP-Link routers to steal Microsoft 365 account credentials.</description><pubDate>Tue, 07 Apr 2026 16:28:36 GMT</pubDate><category>APT28</category><category>FrostArmada</category><category>DNS Hijacking</category><category>Microsoft 365</category><category>MikroTik</category><category>TP Link</category><category>Credential Theft</category></item><item><title>Star Blizzard (APT28) Adopts DarkSword iOS Exploit Kit</title><link>https://runtimerebel.com/blog/star-blizzard-apt28-adopts-darksword-ios-exploit-kit</link><guid isPermaLink="true">https://runtimerebel.com/blog/star-blizzard-apt28-adopts-darksword-ios-exploit-kit</guid><description>Russian APT Star Blizzard (APT28) now uses the DarkSword iOS exploit kit to target government, finance, and academia, increasing mobile threat exposure.</description><pubDate>Mon, 30 Mar 2026 12:35:23 GMT</pubDate><category>Star Blizzard</category><category>APT28</category><category>Fancy Bear</category><category>Nobelium</category><category>DarkSword</category><category>iOS</category><category>Exploit Kit</category><category>State Sponsored</category><category>Mobile Security</category><category>Spear Phishing</category></item><item><title>APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit</title><link>https://runtimerebel.com/blog/apt28-targets-ukraine-via-cve-2024-45519-zimbra-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-targets-ukraine-via-cve-2024-45519-zimbra-exploit</guid><description>Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.</description><pubDate>Thu, 19 Mar 2026 16:25:10 GMT</pubDate><category>APT28</category><category>Zimbra</category><category>CVE-2024-45519</category><category>Ukraine</category><category>SSSCIP</category><category>GRU</category></item><item><title>Sednit/APT28 Resurfaces: Advanced Toolkit Threat Analysis</title><link>https://runtimerebel.com/blog/sednit-apt28-resurfaces-advanced-toolkit-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/sednit-apt28-resurfaces-advanced-toolkit-threat-analysis</guid><description>Russian-affiliated APT Sednit (APT28) has returned with sophisticated new malware, shifting from simple implants. Understand their updated TTPs and mitigation strategies.</description><pubDate>Tue, 10 Mar 2026 20:14:43 GMT</pubDate><category>Sednit</category><category>APT28</category><category>Russia</category><category>Nation State</category><category>Malware</category><category>Toolkit</category></item><item><title>AI-Enhanced Cyberattacks: Microsoft Details LLM Abuse by APT Groups</title><link>https://runtimerebel.com/blog/ai-enhanced-cyberattacks-microsoft-details-llm-abuse-by-apt-groups</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-enhanced-cyberattacks-microsoft-details-llm-abuse-by-apt-groups</guid><description>Microsoft reveals how nation-state actors like APT28 and Crimson Sandstorm are using AI to automate reconnaissance and refine social engineering lures.</description><pubDate>Sat, 07 Mar 2026 16:08:45 GMT</pubDate><category>AI</category><category>Microsoft</category><category>APT28</category><category>LLM</category><category>Forest Blizzard</category><category>Crimson Sandstorm</category></item><item><title>Russian Coruna iOS Exploit Kit Targets Global Users — Analysis</title><link>https://runtimerebel.com/blog/russian-coruna-ios-exploit-kit-targets-global-users-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-coruna-ios-exploit-kit-targets-global-users-analysis</guid><description>Security researchers uncover the Coruna iOS exploit kit, a nation-state tool now used in broader campaigns to deliver spyware to mobile devices.</description><pubDate>Thu, 05 Mar 2026 04:40:41 GMT</pubDate><category>Coruna</category><category>iOS Spyware</category><category>APT28</category><category>Google TAG</category><category>iVerify</category><category>Mobile Security</category></item><item><title>APT28 Exploits CVE-2026-21513: MSHTML 0-Day Intelligence</title><link>https://runtimerebel.com/blog/apt28-exploits-cve-2026-21513-mshtml-0-day-intelligence</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-exploits-cve-2026-21513-mshtml-0-day-intelligence</guid><description>Akamai reports Russia-linked APT28 exploited CVE-2026-21513 in the MSHTML Framework as a zero-day before Microsoft&apos;s February 2026 security patch updates.</description><pubDate>Mon, 02 Mar 2026 12:17:40 GMT</pubDate><category>CVE-2026-21513</category><category>APT28</category><category>MSHTML Framework</category><category>Zero-Day</category><category>Microsoft</category></item><item><title>January 2026 CVE Landscape: APT28 Zero-Day &amp; Critical Flaws</title><link>https://runtimerebel.com/blog/january-2026-cve-landscape-apt28-zero-day-critical-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/january-2026-cve-landscape-apt28-zero-day-critical-flaws</guid><description>Runtime Rebel details January 2026&apos;s 23 critical CVEs, including an APT28 zero-day in Microsoft Office and critical enterprise authentication bypass vulnerabilities.</description><pubDate>Wed, 25 Feb 2026 04:47:44 GMT</pubDate><category>APT28</category><category>Microsoft Office</category><category>Zero-Day</category><category>Authentication Bypass</category><category>Enterprise Systems</category><category>January 2026</category><category>CVE Landscape</category></item><item><title>APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe</title><link>https://runtimerebel.com/blog/apt28-operation-macromaze-webhook-driven-macro-execution-targeting-western-europe</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-operation-macromaze-webhook-driven-macro-execution-targeting-western-europe</guid><description>Analysis of a targeted campaign attributed to APT28, utilizing macro-enabled documents and legitimate webhook services for command-and-control obfuscation.</description><pubDate>Tue, 24 Feb 2026 04:40:50 GMT</pubDate><category>APT28</category><category>MacroMaze</category><category>Webhooks</category><category>Russia</category><category>Espionage</category></item></channel></rss>