<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #China</title><description>Cybersecurity articles tagged #China on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Flying Eagle Mobile RAT Builder: China&apos;s Infostealer-as-a-Service</title><link>https://runtimerebel.com/blog/flying-eagle-mobile-rat-builder-china-s-infostealer-as-a-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/flying-eagle-mobile-rat-builder-china-s-infostealer-as-a-service</guid><description>Analysis of the &apos;Flying Eagle&apos; mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…</description><pubDate>Thu, 30 Jul 2026 02:32:07 GMT</pubDate><category>Flying Eagle</category><category>Mobile RAT</category><category>Android Malware</category><category>Infostealer</category><category>Malware as a Service</category><category>Financial Fraud</category><category>China</category></item><item><title>US Humanoid Robot Ban: Mitigating Chinese Supply Chain Risks</title><link>https://runtimerebel.com/blog/us-humanoid-robot-ban-mitigating-chinese-supply-chain-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-humanoid-robot-ban-mitigating-chinese-supply-chain-risks</guid><description>The U.S. ban on foreign-made humanoid robots highlights growing concerns over data exfiltration and national security risks linked to Chinese manufacturing.</description><pubDate>Wed, 29 Jul 2026 14:14:03 GMT</pubDate><category>China</category><category>Supply Chain</category><category>National Security</category><category>Robotics</category><category>Espionage</category></item><item><title>China Military Bans Top Cybersecurity Firms for Procurement Violations</title><link>https://runtimerebel.com/blog/china-military-bans-top-cybersecurity-firms-for-procurement-violations</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-military-bans-top-cybersecurity-firms-for-procurement-violations</guid><description>Major Chinese firms like Qi-An-Xin and Sangfor face PLA procurement bans due to integrity violations, impacting China’s domestic cybersecurity landscape.</description><pubDate>Thu, 16 Jul 2026 10:14:07 GMT</pubDate><category>China</category><category>PLA</category><category>Qi an Xin</category><category>Sangfor</category><category>Supply Chain Risk</category><category>Military Procurement</category></item><item><title>Parallel APT Cyber Espionage Targets Balochistan Police</title><link>https://runtimerebel.com/blog/parallel-apt-cyber-espionage-targets-balochistan-police</link><guid isPermaLink="true">https://runtimerebel.com/blog/parallel-apt-cyber-espionage-targets-balochistan-police</guid><description>Analysis of parallel cyber espionage campaigns by China and India-linked APTs against Pakistan&apos;s Balochistan Police, detailed by SentinelOne.</description><pubDate>Fri, 10 Jul 2026 14:32:36 GMT</pubDate><category>China</category><category>India</category><category>Pakistan</category><category>Balochistan Police</category><category>APT</category><category>Cyber Espionage</category><category>SentinelOne</category><category>Nation State</category></item><item><title>Chinese LLMs Reshape Cyber Defense: Attacker Advantage</title><link>https://runtimerebel.com/blog/chinese-llms-reshape-cyber-defense-attacker-advantage</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-llms-reshape-cyber-defense-attacker-advantage</guid><description>Chinese Large Language Models (LLMs) are poised to shift the cyber defense balance, potentially giving attackers an advantage. Understand the implications.</description><pubDate>Fri, 03 Jul 2026 14:12:28 GMT</pubDate><category>Large Language Models</category><category>AI</category><category>Cyber Defense</category><category>Threat Intelligence</category><category>China</category></item><item><title>Chinese Espionage: Google Workspace Rule Abuse in Research Sectors</title><link>https://runtimerebel.com/blog/chinese-espionage-google-workspace-rule-abuse-in-research-sectors</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-espionage-google-workspace-rule-abuse-in-research-sectors</guid><description>China-linked threat actors exploited REDCap server backdoors and manipulated Google Workspace mail rules to exfiltrate North American research data.</description><pubDate>Tue, 16 Jun 2026 01:12:06 GMT</pubDate><category>REDCap</category><category>Google Workspace</category><category>Cyber Espionage</category><category>China</category><category>Data Exfiltration</category></item><item><title>UNC6508: Chinese Cyberespionage Targets North American Research</title><link>https://runtimerebel.com/blog/unc6508-chinese-cyberespionage-targets-north-american-research</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6508-chinese-cyberespionage-targets-north-american-research</guid><description>Google&apos;s Threat Intelligence Group tracks UNC6508, a Chinese cyberespionage group targeting North American medical, military, and AI research sectors.</description><pubDate>Mon, 15 Jun 2026 14:23:41 GMT</pubDate><category>UNC6508</category><category>Cyber Espionage</category><category>China</category><category>APT</category><category>North America</category><category>Medical Research</category><category>Military</category><category>AI Research</category></item><item><title>Chinese Smishing Network &apos;Outsider&apos; Leverages Gemini AI for Phishing</title><link>https://runtimerebel.com/blog/chinese-smishing-network-outsider-leverages-gemini-ai-for-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-smishing-network-outsider-leverages-gemini-ai-for-phishing</guid><description>Google sues a Chinese smishing network operating &apos;Outsider&apos; PhaaS, accused of using Gemini AI to craft sophisticated phishing messages targeting Americans.</description><pubDate>Fri, 12 Jun 2026 20:51:49 GMT</pubDate><category>Smishing</category><category>Phishing as a Service</category><category>PhaaS</category><category>Outsider</category><category>Gemini AI</category><category>Google</category><category>Cybercrime Network</category><category>China</category><category>Social Engineering</category></item><item><title>JDY Botnet Expansion: China-Linked Reconnaissance on SOHO/IoT Devices</title><link>https://runtimerebel.com/blog/jdy-botnet-expansion-china-linked-reconnaissance-on-soho-iot-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/jdy-botnet-expansion-china-linked-reconnaissance-on-soho-iot-devices</guid><description>China-linked JDY botnet now controls 1,500+ SOHO/IoT devices, actively expanding cyber reconnaissance for state-sponsored operations.</description><pubDate>Wed, 10 Jun 2026 17:13:48 GMT</pubDate><category>JDY</category><category>Botnet</category><category>China</category><category>SOHO</category><category>IoT</category><category>Cyber Reconnaissance</category><category>State Sponsored</category><category>Threat Intelligence</category></item><item><title>Five Eyes Warning: Chinese Intelligence Job Recruitment Tactics</title><link>https://runtimerebel.com/blog/five-eyes-warning-chinese-intelligence-job-recruitment-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/five-eyes-warning-chinese-intelligence-job-recruitment-tactics</guid><description>Five Eyes agencies issue an advisory on Chinese intelligence officers using fake job offers on professional sites to recruit personnel with security clearances.</description><pubDate>Fri, 05 Jun 2026 09:18:00 GMT</pubDate><category>Five Eyes</category><category>China</category><category>Social Engineering</category><category>Insider Threat</category><category>Recruitment Fraud</category></item><item><title>TA4922 Expands Global Cybercrime: Analysis of Diverse TTPs</title><link>https://runtimerebel.com/blog/ta4922-expands-global-cybercrime-analysis-of-diverse-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/ta4922-expands-global-cybercrime-analysis-of-diverse-ttps</guid><description>Runtime Rebel analyzes TA4922&apos;s expanding global cybercrime operations, detailing diverse TTPs and providing actionable mitigation strategies for security professionals.</description><pubDate>Fri, 05 Jun 2026 05:37:51 GMT</pubDate><category>TA4922</category><category>Cybercrime</category><category>China</category><category>Phishing</category><category>Malware Distribution</category></item><item><title>China&apos;s Dual-Method Cyberattack Targets Czech, Taiwan Orgs with Azureveil</title><link>https://runtimerebel.com/blog/china-s-dual-method-cyberattack-targets-czech-taiwan-orgs-with-azureveil</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-s-dual-method-cyberattack-targets-czech-taiwan-orgs-with-azureveil</guid><description>Nation-state actors linked to China employ dual-method spear-phishing with Azureveil malware to target Czech and Taiwan organizations for data theft.</description><pubDate>Tue, 02 Jun 2026 21:12:29 GMT</pubDate><category>China</category><category>Azureveil</category><category>Spear Phishing</category><category>Data Theft</category><category>Czech Republic</category><category>Taiwan</category><category>Nation State</category></item><item><title>China-Linked UAT-8302 Targets Governments with Custom APT Malware</title><link>https://runtimerebel.com/blog/china-linked-uat-8302-targets-governments-with-custom-apt-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-uat-8302-targets-governments-with-custom-apt-malware</guid><description>UAT-8302, a China-linked threat group, targets government entities in South America and SE Europe using custom malware and shared APT toolsets.</description><pubDate>Tue, 05 May 2026 16:39:00 GMT</pubDate><category>UAT 8302</category><category>China</category><category>APT</category><category>Cisco Talos</category><category>Cyber Espionage</category></item><item><title>US Strategic Pivot: Cyber Risk and Geopolitical Shift Analysis</title><link>https://runtimerebel.com/blog/us-strategic-pivot-cyber-risk-and-geopolitical-shift-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-strategic-pivot-cyber-risk-and-geopolitical-shift-analysis</guid><description>Analysis of the US strategic shift toward force-driven security and its implications for cyber threats from China, Russia, Iran, and criminal groups.</description><pubDate>Thu, 30 Apr 2026 16:41:48 GMT</pubDate><category>Geopolitics</category><category>China</category><category>Russia</category><category>Iran</category><category>Transnational Organized Crime</category><category>Western Hemisphere</category></item><item><title>Alleged Silk Typhoon Hacker Extradited: Cyberespionage Threat</title><link>https://runtimerebel.com/blog/alleged-silk-typhoon-hacker-extradited-cyberespionage-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/alleged-silk-typhoon-hacker-extradited-cyberespionage-threat</guid><description>An alleged Silk Typhoon hacker, associated with Chinese intelligence, has been extradited to the US, highlighting persistent nation-state cyberespionage threats.</description><pubDate>Mon, 27 Apr 2026 20:30:07 GMT</pubDate><category>Silk Typhoon</category><category>Volt Typhoon</category><category>Cyber Espionage</category><category>Nation State</category><category>China</category><category>Extradition</category><category>APT</category></item><item><title>Chinese Spear-Phishing Campaign Targets NASA Defense Software</title><link>https://runtimerebel.com/blog/chinese-spear-phishing-campaign-targets-nasa-defense-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-spear-phishing-campaign-targets-nasa-defense-software</guid><description>NASA OIG reveals a multi-year spear-phishing campaign by a Chinese national impersonating researchers to exfiltrate sensitive U.S. defense software.</description><pubDate>Fri, 24 Apr 2026 16:25:59 GMT</pubDate><category>NASA</category><category>China</category><category>Spear Phishing</category><category>Export Control</category><category>Defense Software</category><category>OIG Report</category></item><item><title>Chinese State-Backed Actors Industrialize Botnets for Covert Ops</title><link>https://runtimerebel.com/blog/chinese-state-backed-actors-industrialize-botnets-for-covert-ops</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-state-backed-actors-industrialize-botnets-for-covert-ops</guid><description>Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.</description><pubDate>Fri, 24 Apr 2026 00:47:01 GMT</pubDate><category>China</category><category>State Backed</category><category>Botnet</category><category>APT</category><category>Cyber Espionage</category><category>Industrialized Botnets</category></item><item><title>UK Cyber Chief: Russia, Iran, China Drive Top Cyber Threats</title><link>https://runtimerebel.com/blog/uk-cyber-chief-russia-iran-china-drive-top-cyber-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-cyber-chief-russia-iran-china-drive-top-cyber-threats</guid><description>NCSC warns British businesses of escalating cyber threats from state-sponsored groups in Russia, Iran, and China, urging preparedness for potential large-scale attacks.</description><pubDate>Wed, 22 Apr 2026 20:26:36 GMT</pubDate><category>UK</category><category>NCSC</category><category>Russia</category><category>Iran</category><category>China</category><category>Nation State</category><category>Cyber Warfare</category><category>Critical Infrastructure</category></item><item><title>Malicious Crypto Wallets Infiltrate China&apos;s Apple App Store</title><link>https://runtimerebel.com/blog/malicious-crypto-wallets-infiltrate-china-s-apple-app-store</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-crypto-wallets-infiltrate-china-s-apple-app-store</guid><description>26 fake cryptocurrency wallet apps infiltrated China&apos;s Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.</description><pubDate>Tue, 21 Apr 2026 00:45:03 GMT</pubDate><category>Cryptocurrency</category><category>Malware</category><category>iOS</category><category>Apple App Store</category><category>Wallet</category><category>Seed Phrase Theft</category><category>China</category><category>Supply Chain Attack</category></item><item><title>FBI Warning: Assessing Data Security Risks of Chinese Mobile Applications</title><link>https://runtimerebel.com/blog/fbi-warning-assessing-data-security-risks-of-chinese-mobile-applications</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warning-assessing-data-security-risks-of-chinese-mobile-applications</guid><description>The FBI warns against data security risks associated with foreign-developed mobile applications, particularly Chinese apps, due to potential data exfiltration.</description><pubDate>Wed, 01 Apr 2026 12:27:27 GMT</pubDate><category>Mobile Security</category><category>Data Privacy</category><category>FBI Warning</category><category>Data Exfiltration</category><category>China</category><category>Supply Chain Risk</category></item><item><title>China-Linked APT Clusters Target SE Asian Government via HIUPAN</title><link>https://runtimerebel.com/blog/china-linked-apt-clusters-target-se-asian-government-via-hiupan</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-apt-clusters-target-se-asian-government-via-hiupan</guid><description>Three China-linked threat clusters targeted a Southeast Asian government in 2025 using HIUPAN, PUBLOAD, and EggStremeFuel malware in a complex espionage operation.</description><pubDate>Mon, 30 Mar 2026 08:39:27 GMT</pubDate><category>China</category><category>Hiupan</category><category>Pubload</category><category>Eggstremefuel</category><category>Southeast Asia</category><category>APT</category><category>Malware</category></item><item><title>Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos</title><link>https://runtimerebel.com/blog/red-menshen-apt-deploys-upgraded-bpfdoor-backdoor-against-telcos</link><guid isPermaLink="true">https://runtimerebel.com/blog/red-menshen-apt-deploys-upgraded-bpfdoor-backdoor-against-telcos</guid><description>Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.</description><pubDate>Fri, 27 Mar 2026 20:16:14 GMT</pubDate><category>Red Menshen</category><category>BPFdoor</category><category>APT</category><category>Telecommunications</category><category>China</category><category>Backdoor</category><category>Espionage</category></item><item><title>EU Sanctions China and Iran Entities Over APT31 Cyber Operations</title><link>https://runtimerebel.com/blog/eu-sanctions-china-and-iran-entities-over-apt31-cyber-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/eu-sanctions-china-and-iran-entities-over-apt31-cyber-operations</guid><description>The European Union imposes sanctions on Chinese and Iranian entities linked to APT31 and state-sponsored cyber espionage targeting democratic institutions.</description><pubDate>Thu, 19 Mar 2026 08:18:51 GMT</pubDate><category>APT31</category><category>Wuhan Xiaoruizhi</category><category>Sanctions</category><category>China</category><category>Iran</category><category>Cyber Diplomacy</category></item><item><title>UAT-9244 Targets South American Telcos with Custom Malware Toolkit</title><link>https://runtimerebel.com/blog/uat-9244-targets-south-american-telcos-with-custom-malware-toolkit</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-9244-targets-south-american-telcos-with-custom-malware-toolkit</guid><description>Chinese state-sponsored actor UAT-9244 targets telecommunications in South America using FaceFish and TinyShell malware to exploit network edge devices.</description><pubDate>Fri, 06 Mar 2026 00:38:51 GMT</pubDate><category>UAT 9244</category><category>FaceFish</category><category>TinyShell</category><category>Telecommunications</category><category>South America</category><category>China</category></item><item><title>Google Forecasts 90 Enterprise Zero-Day Exploits in 2025</title><link>https://runtimerebel.com/blog/google-forecasts-90-enterprise-zero-day-exploits-in-2025</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-forecasts-90-enterprise-zero-day-exploits-in-2025</guid><description>Google predicts half of the 90 exploited zero-day vulnerabilities in 2025 will target enterprises. Understand attribution and proactive defense strategies.</description><pubDate>Thu, 05 Mar 2026 16:26:00 GMT</pubDate><category>Zero-Day</category><category>Enterprise Security</category><category>Google TAG</category><category>Exploitation Trends</category><category>Spyware</category><category>China</category></item><item><title>Meta Files Lawsuits Against Global Celeb-Bait Scam Networks</title><link>https://runtimerebel.com/blog/meta-files-lawsuits-against-global-celeb-bait-scam-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/meta-files-lawsuits-against-global-celeb-bait-scam-networks</guid><description>Meta takes legal action against advertisers in Brazil, China, and Vietnam, disabling accounts and domains used in large-scale celebrity-bait fraud schemes.</description><pubDate>Fri, 27 Feb 2026 08:17:57 GMT</pubDate><category>Meta</category><category>Social Engineering</category><category>Phishing</category><category>Celeb Bait</category><category>Brazil</category><category>China</category><category>Vietnam</category><category>Advertising Fraud</category></item><item><title>Chinese Police Use ChatGPT in Influence Operations Against Japan</title><link>https://runtimerebel.com/blog/chinese-police-use-chatgpt-in-influence-operations-against-japan</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-police-use-chatgpt-in-influence-operations-against-japan</guid><description>Chinese police reportedly used ChatGPT for politically motivated influence operations to smear Japan&apos;s PM Takaichi, highlighting AI&apos;s role in disinformation campaigns.</description><pubDate>Thu, 26 Feb 2026 00:33:49 GMT</pubDate><category>ChatGPT</category><category>Influence Operations</category><category>Disinformation</category><category>Nation State</category><category>China</category><category>Japan</category><category>AI</category><category>Cyber Espionage</category></item><item><title>Google Disrupts Chinese Espionage Actor UNC2814 Targeting Telecoms</title><link>https://runtimerebel.com/blog/google-disrupts-chinese-espionage-actor-unc2814-targeting-telecoms</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-disrupts-chinese-espionage-actor-unc2814-targeting-telecoms</guid><description>Google and Mandiant disrupt UNC2814, a Chinese state-sponsored actor active since 2017, targeting 42 countries across telecom and government sectors.</description><pubDate>Wed, 25 Feb 2026 16:34:10 GMT</pubDate><category>UNC2814</category><category>China</category><category>Cyber Espionage</category><category>Google TAG</category><category>Mandiant</category><category>Telecommunications</category><category>State Sponsored</category></item></channel></rss>