<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #C2</title><description>Cybersecurity articles tagged #C2 on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Aeternum Botnet Leverages Polygon Blockchain for Resilient C2</title><link>https://runtimerebel.com/blog/aeternum-botnet-leverages-polygon-blockchain-for-resilient-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/aeternum-botnet-leverages-polygon-blockchain-for-resilient-c2</guid><description>Aeternum botnet uses Polygon blockchain smart contracts for C2, making it resilient to takedowns. Security professionals must understand its decentralized operations.</description><pubDate>Tue, 11 Aug 2026 01:00:31 GMT</pubDate><category>Botnet</category><category>Malware</category><category>Aeternum</category><category>Polygon Blockchain</category><category>C2</category></item><item><title>Direct-to-IP Malware C2 Bypass: Threat Landscape and ZT‑IP Mitigation</title><link>https://runtimerebel.com/blog/direct-to-ip-malware-c2-bypass-threat-landscape-and-zt-ip-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/direct-to-ip-malware-c2-bypass-threat-landscape-and-zt-ip-mitigation</guid><description>Nearly half of malware samples use hard‑coded IPs for C2, evading DNS defenses; learn detection and mitigation with ZT‑IP.</description><pubDate>Thu, 06 Aug 2026 01:58:07 GMT</pubDate><category>Phorpiex</category><category>Direct to IP</category><category>C2</category><category>Zero Trust IP</category><category>Malware</category></item><item><title>HollowGraph Malware Uses Microsoft Graph for Stealthy C2</title><link>https://runtimerebel.com/blog/hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2</guid><description>HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.</description><pubDate>Mon, 20 Jul 2026 18:05:43 GMT</pubDate><category>HollowGraph</category><category>Microsoft Graph</category><category>Microsoft 365</category><category>C2</category><category>Data Exfiltration</category><category>API Abuse</category></item><item><title>HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2</title><link>https://runtimerebel.com/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2</guid><description>HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.</description><pubDate>Mon, 20 Jul 2026 18:05:24 GMT</pubDate><category>HollowGraph</category><category>Microsoft 365</category><category>Microsoft Graph API</category><category>Espionage</category><category>C2</category><category>Data Exfiltration</category><category>Group IB</category></item><item><title>MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2</title><link>https://runtimerebel.com/blog/modbeacon-rat-silver-fox-uses-grpc-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/modbeacon-rat-silver-fox-uses-grpc-for-stealthy-c2</guid><description>A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.</description><pubDate>Fri, 10 Jul 2026 14:30:03 GMT</pubDate><category>MODBEACON</category><category>RAT</category><category>Silver Fox</category><category>gRPC</category><category>C2</category><category>Rust</category><category>SEO Poisoning</category></item><item><title>Google Disrupts NetNut Malicious Residential Proxy Network</title><link>https://runtimerebel.com/blog/google-disrupts-netnut-malicious-residential-proxy-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-disrupts-netnut-malicious-residential-proxy-network</guid><description>Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.</description><pubDate>Fri, 03 Jul 2026 07:31:53 GMT</pubDate><category>NetNut</category><category>Residential Proxy</category><category>Botnet</category><category>C2</category><category>Google Play Protect</category><category>Malware</category><category>IPIDEA</category><category>Cybercrime</category><category>Espionage</category></item><item><title>Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks</title><link>https://runtimerebel.com/blog/mustang-panda-exploits-zoho-workdrive-for-c2-in-indian-govt-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/mustang-panda-exploits-zoho-workdrive-for-c2-in-indian-govt-attacks</guid><description>Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.</description><pubDate>Mon, 29 Jun 2026 17:06:24 GMT</pubDate><category>Mustang Panda</category><category>APT</category><category>Zoho WorkDrive</category><category>Indian Government</category><category>Espionage</category><category>C2</category><category>Cloud Security</category></item><item><title>GopherWhisper APT Abuses Outlook and Slack for Stealthy C2</title><link>https://runtimerebel.com/blog/gopherwhisper-apt-abuses-outlook-and-slack-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/gopherwhisper-apt-abuses-outlook-and-slack-for-stealthy-c2</guid><description>Newly discovered GopherWhisper APT group uses a Go-based toolkit and legitimate SaaS platforms like Slack and Outlook to conduct espionage against governments.</description><pubDate>Thu, 23 Apr 2026 12:29:29 GMT</pubDate><category>GopherWhisper</category><category>APT</category><category>C2</category><category>Outlook</category><category>Slack</category><category>Discord</category><category>Go Malware</category></item><item><title>SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware</title><link>https://runtimerebel.com/blog/systembc-c2-analysis-1570-victims-of-the-gentlemen-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/systembc-c2-analysis-1570-victims-of-the-gentlemen-ransomware</guid><description>Analysis of a SystemBC C2 server linked to The Gentlemen ransomware reveals over 1,570 victims and the use of SOCKS5 tunnels for persistent access.</description><pubDate>Tue, 21 Apr 2026 20:22:49 GMT</pubDate><category>SystemBC</category><category>The Gentlemen</category><category>Ransomware</category><category>Botnet</category><category>Check Point</category><category>C2</category></item><item><title>Emoji-Based C2: Threat Actors Adopt Covert Communication Tactics</title><link>https://runtimerebel.com/blog/emoji-based-c2-threat-actors-adopt-covert-communication-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/emoji-based-c2-threat-actors-adopt-covert-communication-tactics</guid><description>Threat actors are increasingly using emojis for covert Command and Control communications to evade security filters. Learn how to detect these obfuscated TTPs.</description><pubDate>Thu, 09 Apr 2026 00:35:54 GMT</pubDate><category>Emoji</category><category>Covert Communication</category><category>C2</category><category>Threat Actor TTPs</category><category>Evasion</category><category>Obfuscation</category></item><item><title>SnappyClient C2 Implant Targets Crypto Wallets for Data Theft</title><link>https://runtimerebel.com/blog/snappyclient-c2-implant-targets-crypto-wallets-for-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/snappyclient-c2-implant-targets-crypto-wallets-for-data-theft</guid><description>A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.</description><pubDate>Thu, 19 Mar 2026 00:37:20 GMT</pubDate><category>SnappyClient</category><category>C2</category><category>Crypto Wallets</category><category>Data Theft</category><category>Remote Access</category><category>Malware</category></item><item><title>Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active</title><link>https://runtimerebel.com/blog/tag-poisoning-compromises-xygeni-github-action-c2-implant-active</link><guid isPermaLink="true">https://runtimerebel.com/blog/tag-poisoning-compromises-xygeni-github-action-c2-implant-active</guid><description>Attackers compromised the `xygeni/xygeni-action` GitHub Action using tag poisoning, deploying a C2 implant for up to a week. Users must verify integrity and review logs.</description><pubDate>Thu, 12 Mar 2026 00:30:26 GMT</pubDate><category>GitHub Actions</category><category>Supply Chain Attack</category><category>Tag Poisoning</category><category>Xygeni</category><category>C2</category></item><item><title>North Korean Malicious npm Packages: Detecting Contagious Interview</title><link>https://runtimerebel.com/blog/north-korean-malicious-npm-packages-detecting-contagious-interview</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-malicious-npm-packages-detecting-contagious-interview</guid><description>North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.</description><pubDate>Mon, 02 Mar 2026 12:18:05 GMT</pubDate><category>NPM</category><category>Lazarus Group</category><category>Contagious Interview</category><category>Supply Chain Attack</category><category>Pastebin</category><category>C2</category><category>Node Js</category></item><item><title>GRIDTIDE Espionage: PRC-Nexus UNC2814 Targets Telecoms Globally</title><link>https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</link><guid isPermaLink="true">https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</guid><description>Google disrupts GRIDTIDE, a novel backdoor used by PRC-nexus UNC2814 for global cyber espionage against telecommunications and government entities.</description><pubDate>Wed, 25 Feb 2026 16:34:59 GMT</pubDate><category>UNC2814</category><category>GRIDTIDE</category><category>PRC Nexus</category><category>Cyber Espionage</category><category>Telecommunications</category><category>Government</category><category>Google Sheets API</category><category>SoftEther VPN</category><category>C2</category><category>Linux Malware</category><category>TTPs</category></item><item><title>Kimwolf Botnet Integration Impairs I2P Network Infrastructure</title><link>https://runtimerebel.com/blog/kimwolf-botnet-integration-impairs-i2p-network-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-botnet-integration-impairs-i2p-network-infrastructure</guid><description>The Kimwolf IoT botnet has weaponized the Invisible Internet Project (I2P) to harden its C2 infrastructure, leading to widespread peer instability and network-wide…</description><pubDate>Mon, 23 Feb 2026 08:21:39 GMT</pubDate><category>IoT</category><category>Botnet</category><category>I2P</category><category>C2</category><category>DDoS</category><category>Anonymization</category></item></channel></rss>