<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #China Linked</title><description>Cybersecurity articles tagged #China Linked on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Roundcube Flaw Exploited by China-Linked Group Against Academics</title><link>https://runtimerebel.com/blog/roundcube-flaw-exploited-by-china-linked-group-against-academics</link><guid isPermaLink="true">https://runtimerebel.com/blog/roundcube-flaw-exploited-by-china-linked-group-against-academics</guid><description>A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.</description><pubDate>Wed, 08 Jul 2026 21:35:37 GMT</pubDate><category>Roundcube</category><category>Academic Sector</category><category>Credential Theft</category><category>Backdoor</category><category>China Linked</category><category>Espionage</category><category>Universities</category></item><item><title>UAT-7810 Expands LapDogs ORB Network via LONGLEASH Malware</title><link>https://runtimerebel.com/blog/uat-7810-expands-lapdogs-orb-network-via-longleash-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-7810-expands-lapdogs-orb-network-via-longleash-malware</guid><description>China-linked actor UAT-7810 is leveraging new LONGLEASH malware to expand the LapDogs ORB network, targeting internet-facing networking devices for proxying.</description><pubDate>Wed, 08 Jul 2026 10:20:49 GMT</pubDate><category>UAT 7810</category><category>LONGLEASH</category><category>LapDogs</category><category>ORB Network</category><category>China Linked</category></item><item><title>China-Linked Espionage Targets REDCap Servers, Stealing Medical Data</title><link>https://runtimerebel.com/blog/china-linked-espionage-targets-redcap-servers-stealing-medical-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-espionage-targets-redcap-servers-stealing-medical-data</guid><description>China-linked threat actors breached exposed REDCap servers, deploying InfiniteRed malware to steal sensitive medical research from a North American institution.</description><pubDate>Mon, 15 Jun 2026 14:23:10 GMT</pubDate><category>China Linked</category><category>REDCap</category><category>INFINITERED</category><category>Medical Sector</category><category>Data Breach</category><category>Espionage</category></item><item><title>JDY Botnet: China-Linked Campaign Targets US Military Networks</title><link>https://runtimerebel.com/blog/jdy-botnet-china-linked-campaign-targets-us-military-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/jdy-botnet-china-linked-campaign-targets-us-military-networks</guid><description>Analysis of the China-linked JDY botnet&apos;s expanded targeting of U.S. military networks, its reconnaissance TTPs, and critical mitigation strategies.</description><pubDate>Wed, 10 Jun 2026 17:15:50 GMT</pubDate><category>JDY Botnet</category><category>Volt Typhoon</category><category>China Linked</category><category>US Military</category><category>Reconnaissance</category><category>National Security</category></item><item><title>TA4922 Expands Phishing Campaigns to Europe and South Africa</title><link>https://runtimerebel.com/blog/ta4922-expands-phishing-campaigns-to-europe-and-south-africa</link><guid isPermaLink="true">https://runtimerebel.com/blog/ta4922-expands-phishing-campaigns-to-europe-and-south-africa</guid><description>China-linked TA4922 threat actor expands targeting to the UK, Germany, Italy, and South Africa using ValleyRAT and Atlas RAT malware in high-tempo attacks.</description><pubDate>Thu, 04 Jun 2026 13:14:44 GMT</pubDate><category>TA4922</category><category>ValleyRAT</category><category>Atlas RAT</category><category>China Linked</category><category>Phishing</category></item><item><title>Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing</title><link>https://runtimerebel.com/blog/silver-fox-deploys-abcdoor-malware-via-tax-themed-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/silver-fox-deploys-abcdoor-malware-via-tax-themed-phishing</guid><description>China-linked threat actor Silver Fox targets Russian and Indian organizations using tax-themed lures to deliver the novel ABCDoor malware via phishing waves.</description><pubDate>Mon, 04 May 2026 12:42:24 GMT</pubDate><category>Silver Fox</category><category>ABCDoor</category><category>Phishing</category><category>India</category><category>Russia</category><category>China Linked</category></item><item><title>Storm-1175: China-Linked Zero-Day Exploits Deploy Medusa Ransomware</title><link>https://runtimerebel.com/blog/storm-1175-china-linked-zero-day-exploits-deploy-medusa-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/storm-1175-china-linked-zero-day-exploits-deploy-medusa-ransomware</guid><description>China-linked actor Storm-1175 is weaponizing zero-day and N-day vulnerabilities in perimeter assets to execute high-velocity Medusa ransomware attacks.</description><pubDate>Tue, 07 Apr 2026 08:33:07 GMT</pubDate><category>Storm 1175</category><category>Medusa Ransomware</category><category>China Linked</category><category>Zero-Day</category><category>Perimeter Security</category></item><item><title>TA416 Targets European Govts with PlugX &amp; OAuth Phishing</title><link>https://runtimerebel.com/blog/ta416-targets-european-govts-with-plugx-oauth-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/ta416-targets-european-govts-with-plugx-oauth-phishing</guid><description>China-linked TA416 has resumed targeting European government and diplomatic entities since mid-2025 using PlugX and OAuth-based phishing attacks.</description><pubDate>Fri, 03 Apr 2026 20:13:24 GMT</pubDate><category>TA416</category><category>DarkPeony</category><category>PlugX</category><category>Oauth Phishing</category><category>APT</category><category>European Governments</category><category>China Linked</category></item></channel></rss>