<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Cryptocurrency Theft</title><description>Cybersecurity articles tagged #Cryptocurrency Theft on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Jewelbug APT: Dual-Motivation Espionage &amp; Crypto Heists</title><link>https://runtimerebel.com/blog/jewelbug-apt-dual-motivation-espionage-crypto-heists</link><guid isPermaLink="true">https://runtimerebel.com/blog/jewelbug-apt-dual-motivation-espionage-crypto-heists</guid><description>Jewelbug APT, a unique &apos;hackers-for-hire&apos; group, conducts state-sponsored espionage and financially motivated cryptocurrency heists from a single operational panel.</description><pubDate>Thu, 13 Aug 2026 16:47:11 GMT</pubDate><category>Cyber Espionage</category><category>Cryptocurrency Theft</category><category>Threat Actor</category><category>Financially Motivated</category><category>Jewelbug APT</category></item><item><title>UAT-11795 Deploys Starland RAT &amp; WLDR Agent in Financial Campaign</title><link>https://runtimerebel.com/blog/uat-11795-deploys-starland-rat-wldr-agent-in-financial-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-11795-deploys-starland-rat-wldr-agent-in-financial-campaign</guid><description>UAT-11795, a Russian-speaking financially motivated adversary, uses Starland RAT and the WLDR C2 agent to target credentials and crypto in the U.S. and Europe.</description><pubDate>Sat, 08 Aug 2026 16:24:54 GMT</pubDate><category>Financially Motivated</category><category>Credential Theft</category><category>Cryptocurrency Theft</category><category>UAT 11795</category><category>Starland RAT</category></item><item><title>Apple App Store Fraud: Fake Sparrow Wallet Steals $1.8M in Bitcoin</title><link>https://runtimerebel.com/blog/apple-app-store-fraud-fake-sparrow-wallet-steals-1-8m-in-bitcoin</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-app-store-fraud-fake-sparrow-wallet-steals-1-8m-in-bitcoin</guid><description>A fraudulent Sparrow Wallet application on the Apple App Store has resulted in a $1.8 million Bitcoin theft, sparking a lawsuit over platform security claims.</description><pubDate>Mon, 27 Jul 2026 17:43:38 GMT</pubDate><category>Cryptocurrency Theft</category><category>Apple App Store</category><category>Sparrow Wallet</category><category>Malicious Apps</category><category>Bitcoin Fraud</category></item><item><title>BlueNoroff Zoom Phishing Kit Targets Crypto Wallets</title><link>https://runtimerebel.com/blog/bluenoroff-zoom-phishing-kit-targets-crypto-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/bluenoroff-zoom-phishing-kit-targets-crypto-wallets</guid><description>BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.</description><pubDate>Fri, 24 Jul 2026 17:39:06 GMT</pubDate><category>BlueNoroff</category><category>Lazarus Group</category><category>Cryptocurrency Theft</category><category>ClickFix</category><category>Phishing</category></item><item><title>OkoBot Framework: Multi-Payload Data &amp; Crypto Theft Attacks</title><link>https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</guid><description>The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data.</description><pubDate>Thu, 16 Jul 2026 21:02:27 GMT</pubDate><category>OkoBot</category><category>Malware</category><category>Infostealer</category><category>Cryptocurrency Theft</category><category>Credential Theft</category><category>Data Exfiltration</category></item><item><title>SIM-Swapping Ring Busted: Millions in Crypto Theft via Telecom Hacks</title><link>https://runtimerebel.com/blog/sim-swapping-ring-busted-millions-in-crypto-theft-via-telecom-hacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/sim-swapping-ring-busted-millions-in-crypto-theft-via-telecom-hacks</guid><description>Polish authorities dismantle a sophisticated SIM-swapping ring that hijacked telecom partners and email accounts to steal millions in cryptocurrency.</description><pubDate>Fri, 26 Jun 2026 01:02:30 GMT</pubDate><category>SIM Swapping</category><category>Cryptocurrency Theft</category><category>Telecommunications Security</category><category>Account Takeover</category><category>Cybercrime</category><category>Poland</category></item><item><title>Cross-Platform Clipboard Hijacker: Fake Reputation Campaign Targets Crypto</title><link>https://runtimerebel.com/blog/cross-platform-clipboard-hijacker-fake-reputation-campaign-targets-crypto</link><guid isPermaLink="true">https://runtimerebel.com/blog/cross-platform-clipboard-hijacker-fake-reputation-campaign-targets-crypto</guid><description>Analysis of a cross-platform clipboard hijacker spread via elaborate fake reputation campaigns on GitHub, YouTube, and VirusTotal to steal cryptocurrency.</description><pubDate>Mon, 22 Jun 2026 17:39:28 GMT</pubDate><category>Clipboard Hijacker</category><category>Cryptocurrency Theft</category><category>Social Engineering</category><category>Fake Reputation</category><category>Cross Platform Malware</category></item><item><title>Crypto Gang Sentencing: Inside the $243M Greavys Group Heist</title><link>https://runtimerebel.com/blog/crypto-gang-sentencing-inside-the-243m-greavys-group-heist</link><guid isPermaLink="true">https://runtimerebel.com/blog/crypto-gang-sentencing-inside-the-243m-greavys-group-heist</guid><description>A 20-year-old gang member receives a 6.5-year sentence for his role in a $243 million crypto heist involving home invasion and social engineering.</description><pubDate>Thu, 07 May 2026 12:46:44 GMT</pubDate><category>Cryptocurrency Theft</category><category>Social Engineering</category><category>Money Laundering</category><category>Greavys Group</category><category>Threat Intel</category></item><item><title>North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026</title><link>https://runtimerebel.com/blog/north-korea-dominates-crypto-heists-76-of-stolen-funds-by-2026</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korea-dominates-crypto-heists-76-of-stolen-funds-by-2026</guid><description>North Korean threat actors are projected to be responsible for 76% of all cryptocurrency stolen by 2026, utilizing sophisticated methods for large-scale heists.</description><pubDate>Sat, 02 May 2026 00:49:12 GMT</pubDate><category>North Korea</category><category>Cryptocurrency Theft</category><category>Lazarus Group</category><category>Cybercrime</category><category>Financial Crime</category><category>Nation State APT</category></item><item><title>Lazarus Group&apos;s $2B+ Crypto Theft: Defending Against Supply Chain Attacks</title><link>https://runtimerebel.com/blog/lazarus-group-s-2b-crypto-theft-defending-against-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/lazarus-group-s-2b-crypto-theft-defending-against-supply-chain-attacks</guid><description>An analysis of Lazarus Group&apos;s persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.</description><pubDate>Tue, 28 Apr 2026 16:47:53 GMT</pubDate><category>Lazarus Group</category><category>DPRK</category><category>Cryptocurrency Theft</category><category>Supply Chain Attack</category><category>Financial Cybercrime</category><category>APT</category></item><item><title>Global Law Enforcement Disrupts $45M Crypto Theft Network</title><link>https://runtimerebel.com/blog/global-law-enforcement-disrupts-45m-crypto-theft-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/global-law-enforcement-disrupts-45m-crypto-theft-network</guid><description>International authorities in the US, UK, and Canada freeze $12 million and identify $45 million in stolen assets linked to global crypto theft schemes.</description><pubDate>Mon, 13 Apr 2026 12:32:39 GMT</pubDate><category>Cryptocurrency Theft</category><category>Operation Spincaster</category><category>Pig Butchering</category><category>FBI</category><category>Financial Crime</category></item><item><title>Bitcoin Depot Credential Theft: $3.6M Stolen from Hot Wallets</title><link>https://runtimerebel.com/blog/bitcoin-depot-credential-theft-3-6m-stolen-from-hot-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/bitcoin-depot-credential-theft-3-6m-stolen-from-hot-wallets</guid><description>Bitcoin Depot reports a $3.6 million loss after attackers compromised administrative credentials to drain corporate hot wallets. Analyze the breach and TTPs.</description><pubDate>Thu, 09 Apr 2026 08:43:08 GMT</pubDate><category>Bitcoin Depot</category><category>Cryptocurrency Theft</category><category>Hot Wallet Security</category><category>Credential Compromise</category></item><item><title>DPRK Social Engineering Behind $285 Million Drift Hack: Analysis</title><link>https://runtimerebel.com/blog/dprk-social-engineering-behind-285-million-drift-hack-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-social-engineering-behind-285-million-drift-hack-analysis</guid><description>A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.</description><pubDate>Sun, 05 Apr 2026 20:11:07 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>Drift Protocol</category><category>Social Engineering</category><category>Solana</category><category>Cryptocurrency Theft</category></item><item><title>SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases</title><link>https://runtimerebel.com/blog/sparkcat-mobile-malware-variant-steals-crypto-recovery-phrases</link><guid isPermaLink="true">https://runtimerebel.com/blog/sparkcat-mobile-malware-variant-steals-crypto-recovery-phrases</guid><description>A new SparkCat malware variant targets iOS and Android users, stealing crypto wallet recovery phrase images from compromised apps on official stores.</description><pubDate>Fri, 03 Apr 2026 12:21:17 GMT</pubDate><category>SparkCat</category><category>Mobile Malware</category><category>iOS</category><category>Android</category><category>Cryptocurrency Theft</category><category>App Store Malware</category><category>Recovery Phrase Theft</category></item></channel></rss>