<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Backdoor</title><description>Cybersecurity articles tagged #Backdoor on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Head Mare Breaches TrueConf, Trojanizes Client Installers</title><link>https://runtimerebel.com/blog/head-mare-breaches-trueconf-trojanizes-client-installers</link><guid isPermaLink="true">https://runtimerebel.com/blog/head-mare-breaches-trueconf-trojanizes-client-installers</guid><description>The Head Mare hacktivist group breached TrueConf video conferencing servers to distribute backdoored client installers, compromising user systems.</description><pubDate>Sat, 08 Aug 2026 16:22:32 GMT</pubDate><category>TrueConf</category><category>Head Mare</category><category>Supply Chain Attack</category><category>Backdoor</category><category>Malware</category></item><item><title>Critical Backdoors &amp; Supply Chain Attacks: Zbtlink Routers &amp; QuickFox VPN Compromised</title><link>https://runtimerebel.com/blog/critical-backdoors-supply-chain-attacks-zbtlink-routers-quickfox-vpn-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-backdoors-supply-chain-attacks-zbtlink-routers-quickfox-vpn-compromised</guid><description>Urgent warning: Zbtlink routers ship with unauthenticated root backdoors, while QuickFox VPN delivers FDMTP implant via supply chain compromise.</description><pubDate>Fri, 07 Aug 2026 16:43:45 GMT</pubDate><category>Supply Chain Attack</category><category>Backdoor</category><category>RCE</category><category>Zbtlink</category><category>QuickFox VPN</category></item><item><title>Suspected Chinese-Speaking Hackers Deploy OctLurk, SilkLurk Backdoors</title><link>https://runtimerebel.com/blog/suspected-chinese-speaking-hackers-deploy-octlurk-silklurk-backdoors</link><guid isPermaLink="true">https://runtimerebel.com/blog/suspected-chinese-speaking-hackers-deploy-octlurk-silklurk-backdoors</guid><description>Ongoing cyberattacks by a suspected Chinese-speaking threat actor target Central Asian governments with OctLurk and SilkLurk backdoors for espionage and data theft.</description><pubDate>Sat, 01 Aug 2026 02:54:42 GMT</pubDate><category>Chinese Speaking Hackers</category><category>OctLurk</category><category>SilLurk</category><category>Central Asia</category><category>Government Targets</category><category>Espionage</category><category>Backdoor</category></item><item><title>GigaWiper: Modular Implant Combines Backdoor &amp; Wiper Functions</title><link>https://runtimerebel.com/blog/gigawiper-modular-implant-combines-backdoor-wiper-functions</link><guid isPermaLink="true">https://runtimerebel.com/blog/gigawiper-modular-implant-combines-backdoor-wiper-functions</guid><description>Analysis of GigaWiper, a modular implant allowing threat actors to combine backdoor and wiper functionality for customizable destructive attacks and maximum impact.</description><pubDate>Mon, 13 Jul 2026 18:00:25 GMT</pubDate><category>GigaWiper</category><category>Wiper Malware</category><category>Backdoor</category><category>Modular Malware</category><category>Destructive Attacks</category></item><item><title>Roundcube Flaw Exploited by China-Linked Group Against Academics</title><link>https://runtimerebel.com/blog/roundcube-flaw-exploited-by-china-linked-group-against-academics</link><guid isPermaLink="true">https://runtimerebel.com/blog/roundcube-flaw-exploited-by-china-linked-group-against-academics</guid><description>A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.</description><pubDate>Wed, 08 Jul 2026 21:35:37 GMT</pubDate><category>Roundcube</category><category>Academic Sector</category><category>Credential Theft</category><category>Backdoor</category><category>China Linked</category><category>Espionage</category><category>Universities</category></item><item><title>New &apos;Leash&apos; Backdoors Target SOHO Routers: China-Linked APT Update</title><link>https://runtimerebel.com/blog/new-leash-backdoors-target-soho-routers-china-linked-apt-update</link><guid isPermaLink="true">https://runtimerebel.com/blog/new-leash-backdoors-target-soho-routers-china-linked-apt-update</guid><description>A China-linked APT group has expanded its toolkit with new &apos;Leash&apos; backdoors (LongLeash, DogLeash, JarLeash), targeting SOHO routers for persistent access and command…</description><pubDate>Wed, 08 Jul 2026 17:40:14 GMT</pubDate><category>China Linked APT</category><category>SOHO Routers</category><category>LONGLEASH</category><category>DogLeash</category><category>JarLeash</category><category>Backdoor</category><category>LapDogs Campaign</category></item><item><title>CVE-2026-11405: Tenda Router Firmware Admin Backdoor Exposed</title><link>https://runtimerebel.com/blog/cve-2026-11405-tenda-router-firmware-admin-backdoor-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-11405-tenda-router-firmware-admin-backdoor-exposed</guid><description>CERT/CC warns of an undocumented admin backdoor, CVE-2026-11405, in Tenda router firmware, enabling full administrative access bypass. Immediate action advised.</description><pubDate>Tue, 07 Jul 2026 11:09:22 GMT</pubDate><category>CVE-2026-11405</category><category>Tenda</category><category>Router</category><category>Firmware</category><category>Authentication Bypass</category><category>Backdoor</category><category>CERT CC</category></item><item><title>China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor</title><link>https://runtimerebel.com/blog/china-linked-apt-targets-southeast-asia-critical-systems-with-new-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-apt-targets-southeast-asia-critical-systems-with-new-backdoor</guid><description>A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.</description><pubDate>Wed, 01 Jul 2026 05:41:17 GMT</pubDate><category>China Linked APT</category><category>Southeast Asia</category><category>Critical Infrastructure</category><category>Backdoor</category><category>State Sponsored</category><category>Espionage</category><category>Cyber Warfare</category></item><item><title>ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored</title><link>https://runtimerebel.com/blog/shapedplugin-supply-chain-attack-wordpress-pro-plugins-backdoored</link><guid isPermaLink="true">https://runtimerebel.com/blog/shapedplugin-supply-chain-attack-wordpress-pro-plugins-backdoored</guid><description>Attackers compromised ShapedPlugin&apos;s distribution pipeline to inject backdoors into Pro WordPress plugins. Learn how to detect and remediate this supply chain threat.</description><pubDate>Tue, 23 Jun 2026 00:57:15 GMT</pubDate><category>ShapedPlugin</category><category>WordPress</category><category>Supply Chain Attack</category><category>Backdoor</category><category>Wordfence</category></item><item><title>CryptoBandits Malware: Tor-Abusing Backdoor &amp; Data Theft</title><link>https://runtimerebel.com/blog/cryptobandits-malware-tor-abusing-backdoor-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/cryptobandits-malware-tor-abusing-backdoor-data-theft</guid><description>CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.</description><pubDate>Fri, 19 Jun 2026 16:55:32 GMT</pubDate><category>CryptoBandits</category><category>Backdoor</category><category>Tor</category><category>SOCKS5 Proxy</category><category>Data Theft</category><category>Remote Code Execution</category></item><item><title>Outdated REDCap Servers Targeted by China-linked UNC6508</title><link>https://runtimerebel.com/blog/outdated-redcap-servers-targeted-by-china-linked-unc6508</link><guid isPermaLink="true">https://runtimerebel.com/blog/outdated-redcap-servers-targeted-by-china-linked-unc6508</guid><description>A majority of internet-accessible REDCap servers remain unpatched, making them prime targets for initial access and backdoor deployment by China-linked UNC6508.</description><pubDate>Thu, 18 Jun 2026 17:10:13 GMT</pubDate><category>REDCap</category><category>UNC6508</category><category>Outdated Software</category><category>Healthcare</category><category>Initial Access</category><category>Backdoor</category></item><item><title>SHub Reaper Stealer Backdoors macOS via Spoofed Apps</title><link>https://runtimerebel.com/blog/shub-reaper-stealer-backdoors-macos-via-spoofed-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/shub-reaper-stealer-backdoors-macos-via-spoofed-apps</guid><description>SHub Reaper stealer targets macOS, using fake Google, Microsoft, Apple, WeChat, and Miro installers for Apple script-based execution and backdooring.</description><pubDate>Tue, 19 May 2026 20:42:42 GMT</pubDate><category>SHub Reaper</category><category>macOS</category><category>Stealer</category><category>Backdoor</category><category>Phishing</category><category>AppleScript</category></item><item><title>SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor</title><link>https://runtimerebel.com/blog/shub-macos-infostealer-spoofs-apple-security-updates-installs-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/shub-macos-infostealer-spoofs-apple-security-updates-installs-backdoor</guid><description>A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.</description><pubDate>Tue, 19 May 2026 00:57:05 GMT</pubDate><category>SHub</category><category>macOS</category><category>Infostealer</category><category>AppleScript</category><category>Backdoor</category><category>Phishing</category></item><item><title>Malicious node-ipc Versions Compromise Developer Secrets via Supply Chain</title><link>https://runtimerebel.com/blog/malicious-node-ipc-versions-compromise-developer-secrets-via-supply-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-node-ipc-versions-compromise-developer-secrets-via-supply-chain</guid><description>Three versions of the node-ipc npm package (9.1.6, 9.2.3, 12.0.1) contain stealer/backdoor functionality targeting developer secrets. Urgent update advised.</description><pubDate>Thu, 14 May 2026 20:36:23 GMT</pubDate><category>Node Ipc</category><category>NPM</category><category>Supply Chain Attack</category><category>Developer Secrets</category><category>Backdoor</category><category>Stealer</category></item><item><title>Stealthy Quasar Linux (QLNX) Malware Targets Developers</title><link>https://runtimerebel.com/blog/stealthy-quasar-linux-qlnx-malware-targets-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/stealthy-quasar-linux-qlnx-malware-targets-developers</guid><description>New Quasar Linux (QLNX) malware is infecting developers&apos; Linux systems, utilizing rootkit, backdoor, and credential-stealing techniques. Learn to detect and mitigate.</description><pubDate>Wed, 06 May 2026 00:46:50 GMT</pubDate><category>Quasar Linux</category><category>QLNX</category><category>Linux Malware</category><category>Rootkit</category><category>Backdoor</category><category>Software Developers</category><category>Credential Theft</category></item><item><title>Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia</title><link>https://runtimerebel.com/blog/silver-fox-apt-tax-themed-phishing-delivers-abcdoor-to-india-russia</link><guid isPermaLink="true">https://runtimerebel.com/blog/silver-fox-apt-tax-themed-phishing-delivers-abcdoor-to-india-russia</guid><description>China-backed Silver Fox APT targets organizations in India and Russia with over 1,600 tax-themed phishing messages to deploy ABCDoor backdoor and ValleyRAT.</description><pubDate>Mon, 04 May 2026 16:46:54 GMT</pubDate><category>Silver Fox</category><category>ABCSDoor</category><category>ValleyRAT</category><category>Phishing</category><category>India</category><category>Russia</category><category>APT</category><category>Backdoor</category><category>Tax Themed Attacks</category></item><item><title>WordPress Quick Page/Post Redirect Backdoor: Arbitrary Code Injection</title><link>https://runtimerebel.com/blog/wordpress-quick-page-post-redirect-backdoor-arbitrary-code-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-quick-page-post-redirect-backdoor-arbitrary-code-injection</guid><description>A dormant backdoor in the Quick Page/Post Redirect WordPress plugin allowed arbitrary code injection for five years on over 70,000 sites. Learn mitigation.</description><pubDate>Thu, 30 Apr 2026 00:51:16 GMT</pubDate><category>WordPress</category><category>Quick Page Post Redirect</category><category>Backdoor</category><category>Code Injection</category><category>Supply Chain</category><category>Plugin Vulnerability</category></item><item><title>UNC6692 Targets Microsoft Teams to Deploy Snow Malware</title><link>https://runtimerebel.com/blog/unc6692-targets-microsoft-teams-to-deploy-snow-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6692-targets-microsoft-teams-to-deploy-snow-malware</guid><description>UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.</description><pubDate>Sat, 25 Apr 2026 16:17:06 GMT</pubDate><category>UNC6692</category><category>Microsoft Teams</category><category>SNOW Malware</category><category>Social Engineering</category><category>Backdoor</category><category>Persistence</category></item><item><title>Firestarter Backdoor Infects Cisco Firewall at US Federal Agency</title><link>https://runtimerebel.com/blog/firestarter-backdoor-infects-cisco-firewall-at-us-federal-agency</link><guid isPermaLink="true">https://runtimerebel.com/blog/firestarter-backdoor-infects-cisco-firewall-at-us-federal-agency</guid><description>Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.</description><pubDate>Fri, 24 Apr 2026 12:34:34 GMT</pubDate><category>FIRESTARTER</category><category>Cisco Firewall</category><category>Backdoor</category><category>Federal Agency</category><category>Persistence</category><category>Remote Access</category></item><item><title>FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower &amp; Secure Firewall</title><link>https://runtimerebel.com/blog/firestarter-backdoor-persistent-threat-to-cisco-firepower-secure-firewall</link><guid isPermaLink="true">https://runtimerebel.com/blog/firestarter-backdoor-persistent-threat-to-cisco-firepower-secure-firewall</guid><description>CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.</description><pubDate>Thu, 23 Apr 2026 16:44:19 GMT</pubDate><category>FIRESTARTER</category><category>Cisco Firepower</category><category>Cisco Secure Firewall</category><category>Cisco ASA</category><category>Backdoor</category><category>APT</category><category>CVE-2025-20333</category><category>CVE-2025-20362</category><category>LINE VIPER</category><category>Persistence</category></item><item><title>APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting</title><link>https://runtimerebel.com/blog/apt41-deploys-stealth-backdoor-for-cloud-credential-harvesting</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt41-deploys-stealth-backdoor-for-cloud-credential-harvesting</guid><description>China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.</description><pubDate>Mon, 13 Apr 2026 16:35:11 GMT</pubDate><category>APT41</category><category>Cloud Security</category><category>Credential Harvesting</category><category>AWS</category><category>Azure</category><category>Backdoor</category></item><item><title>Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack</title><link>https://runtimerebel.com/blog/smart-slider-3-pro-3-5-1-35-backdoor-via-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/smart-slider-3-pro-3-5-1-35-backdoor-via-supply-chain-attack</guid><description>Nextend&apos;s Smart Slider 3 Pro version 3.5.1.35 was compromised via a supply chain attack. Learn how to identify and remediate the backdoor today.</description><pubDate>Fri, 10 Apr 2026 08:37:51 GMT</pubDate><category>Smart Slider 3 Pro</category><category>WordPress Security</category><category>Nextend</category><category>Backdoor</category><category>Supply Chain Attack</category></item><item><title>Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos</title><link>https://runtimerebel.com/blog/red-menshen-apt-deploys-upgraded-bpfdoor-backdoor-against-telcos</link><guid isPermaLink="true">https://runtimerebel.com/blog/red-menshen-apt-deploys-upgraded-bpfdoor-backdoor-against-telcos</guid><description>Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.</description><pubDate>Fri, 27 Mar 2026 20:16:14 GMT</pubDate><category>Red Menshen</category><category>BPFdoor</category><category>APT</category><category>Telecommunications</category><category>China</category><category>Backdoor</category><category>Espionage</category></item><item><title>Fake Next.js Job Interview Tests Backdoor Developers</title><link>https://runtimerebel.com/blog/fake-next-js-job-interview-tests-backdoor-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-next-js-job-interview-tests-backdoor-developers</guid><description>Microsoft Defender discovered a campaign where malicious Next.js job interview tests backdoor developers&apos; devices, posing a supply chain risk.</description><pubDate>Thu, 26 Feb 2026 00:33:15 GMT</pubDate><category>Next Js</category><category>Software Developers</category><category>Supply Chain Attack</category><category>Malware</category><category>Backdoor</category><category>Social Engineering</category><category>Job Scams</category><category>Microsoft Defender</category></item><item><title>Malicious npm Package Targets React Developers with Backdoored Polyfill</title><link>https://runtimerebel.com/blog/supply-chain-attack-npm</link><guid isPermaLink="true">https://runtimerebel.com/blog/supply-chain-attack-npm</guid><description>A typosquatted npm package mimicking a popular React utility has been downloaded over 47,000 times before removal.</description><pubDate>Thu, 25 Jan 2024 00:00:00 GMT</pubDate><category>NPM</category><category>Supply Chain</category><category>Typosquatting</category><category>JavaScript</category><category>Backdoor</category></item></channel></rss>