<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Cyber Espionage</title><description>Cybersecurity articles tagged #Cyber Espionage on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>U.S. Sanctions Iran-Linked Hackers Targeting Critical Infrastructure</title><link>https://runtimerebel.com/blog/u-s-sanctions-iran-linked-hackers-targeting-critical-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/u-s-sanctions-iran-linked-hackers-targeting-critical-infrastructure</guid><description>U.S. Treasury sanctions Iran-linked cyber actors, including Mabna Institute members, for critical infrastructure breaches and cyber theft.</description><pubDate>Wed, 26 Aug 2026 00:41:56 GMT</pubDate><category>Iran</category><category>Sanctions</category><category>Critical Infrastructure</category><category>MOIS</category><category>Cyber Espionage</category></item><item><title>Transparent Tribe Targets Afghan and Indian Organizations</title><link>https://runtimerebel.com/blog/transparent-tribe-targets-afghan-and-indian-organizations</link><guid isPermaLink="true">https://runtimerebel.com/blog/transparent-tribe-targets-afghan-and-indian-organizations</guid><description>Pakistan-linked Transparent Tribe updates its malware toolset to target Afghan organizations and government agencies in India.</description><pubDate>Thu, 20 Aug 2026 16:25:29 GMT</pubDate><category>Transparent Tribe</category><category>APT</category><category>Cyber Espionage</category><category>Malware</category></item><item><title>US Charges Iranian Hackers in $3.4B Intellectual Property Theft</title><link>https://runtimerebel.com/blog/us-charges-iranian-hackers-in-3-4b-intellectual-property-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-charges-iranian-hackers-in-3-4b-intellectual-property-theft</guid><description>US charges 17 Iranian hackers from Mabna Institute for a state-sponsored campaign stealing 31.5 TB of academic and corporate intellectual property since 2013.</description><pubDate>Wed, 19 Aug 2026 16:22:00 GMT</pubDate><category>Iran</category><category>Cyber Espionage</category><category>DOJ</category><category>Mabna Institute</category><category>Intellectual Property Theft</category></item><item><title>AI-Driven Cyberattack Targets APAC Government Agencies</title><link>https://runtimerebel.com/blog/ai-driven-cyberattack-targets-apac-government-agencies</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-cyberattack-targets-apac-government-agencies</guid><description>A China-linked actor reportedly deployed a near-autonomous AI framework to compromise government agencies in the APAC region, signaling a new threat landscape.</description><pubDate>Wed, 19 Aug 2026 08:27:30 GMT</pubDate><category>AI</category><category>Cyber Espionage</category><category>Nation State</category><category>APT</category><category>Asia Pacific</category></item><item><title>Jewelbug APT: Dual-Motivation Espionage &amp; Crypto Heists</title><link>https://runtimerebel.com/blog/jewelbug-apt-dual-motivation-espionage-crypto-heists</link><guid isPermaLink="true">https://runtimerebel.com/blog/jewelbug-apt-dual-motivation-espionage-crypto-heists</guid><description>Jewelbug APT, a unique &apos;hackers-for-hire&apos; group, conducts state-sponsored espionage and financially motivated cryptocurrency heists from a single operational panel.</description><pubDate>Thu, 13 Aug 2026 16:47:11 GMT</pubDate><category>Cyber Espionage</category><category>Cryptocurrency Theft</category><category>Threat Actor</category><category>Financially Motivated</category><category>Jewelbug APT</category></item><item><title>CVE-2025-66376: APT28 Exploits Zimbra Zero-Click for Espionage</title><link>https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</guid><description>Russian state-sponsored actors exploit a zero-click Zimbra vulnerability (CVE-2025-66376) to exfiltrate sensitive webmail data from targeted organizations.</description><pubDate>Sat, 08 Aug 2026 08:33:35 GMT</pubDate><category>CVE-2025-66376</category><category>Zimbra</category><category>Cyber Espionage</category><category>Zero Click</category><category>Phishing</category></item><item><title>EU Sanctions Russian Intel Officers for APT28 Cyber Operations</title><link>https://runtimerebel.com/blog/eu-sanctions-russian-intel-officers-for-apt28-cyber-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/eu-sanctions-russian-intel-officers-for-apt28-cyber-operations</guid><description>The EU imposes sanctions on Russian GRU officers linked to APT28 for long-term cyber espionage and sabotage targeting government and infrastructure.</description><pubDate>Mon, 13 Jul 2026 11:22:06 GMT</pubDate><category>APT28</category><category>GRU</category><category>EU Sanctions</category><category>Cyber Espionage</category><category>Critical Infrastructure</category></item><item><title>Parallel APT Cyber Espionage Targets Balochistan Police</title><link>https://runtimerebel.com/blog/parallel-apt-cyber-espionage-targets-balochistan-police</link><guid isPermaLink="true">https://runtimerebel.com/blog/parallel-apt-cyber-espionage-targets-balochistan-police</guid><description>Analysis of parallel cyber espionage campaigns by China and India-linked APTs against Pakistan&apos;s Balochistan Police, detailed by SentinelOne.</description><pubDate>Fri, 10 Jul 2026 14:32:36 GMT</pubDate><category>China</category><category>India</category><category>Pakistan</category><category>Balochistan Police</category><category>APT</category><category>Cyber Espionage</category><category>SentinelOne</category><category>Nation State</category></item><item><title>Iran Cyber Focus Expands: Securing Internet-Facing Vulnerabilities</title><link>https://runtimerebel.com/blog/iran-cyber-focus-expands-securing-internet-facing-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-cyber-focus-expands-securing-internet-facing-vulnerabilities</guid><description>Iranian state-sponsored cyber operations are broadening targets beyond critical infrastructure. All organizations must secure Internet-facing systems.</description><pubDate>Fri, 10 Jul 2026 03:33:44 GMT</pubDate><category>Iran</category><category>Nation State</category><category>Cyber Espionage</category><category>Vulnerability Management</category><category>Internet Facing Vulnerabilities</category></item><item><title>Armored Likho Leverages BusySnake Stealer Against Critical Sectors</title><link>https://runtimerebel.com/blog/armored-likho-leverages-busysnake-stealer-against-critical-sectors</link><guid isPermaLink="true">https://runtimerebel.com/blog/armored-likho-leverages-busysnake-stealer-against-critical-sectors</guid><description>Undocumented threat actor Armored Likho targets government and electric power sectors in Russia, Brazil, and Kazakhstan with BusySnake Stealer.</description><pubDate>Fri, 03 Jul 2026 14:08:59 GMT</pubDate><category>Armored Likho</category><category>BusySnake Stealer</category><category>Government Agencies</category><category>Electric Power Sector</category><category>Cyber Espionage</category><category>Kaspersky</category></item><item><title>Turla&apos;s STOCKSTAY Backdoor: Analysis of Campaigns &amp; WinRAR Exploit</title><link>https://runtimerebel.com/blog/turla-s-stockstay-backdoor-analysis-of-campaigns-winrar-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/turla-s-stockstay-backdoor-analysis-of-campaigns-winrar-exploit</guid><description>Google Threat Intelligence details STOCKSTAY, Turla&apos;s .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP &amp; CVE-2025-8088.</description><pubDate>Fri, 26 Jun 2026 09:21:08 GMT</pubDate><category>Turla</category><category>STOCKSTAY</category><category>KAZUAR</category><category>APT</category><category>Cyber Espionage</category><category>Ukraine</category><category>Government</category><category>Military</category><category>CVE-2025-8088</category><category>WinRAR</category><category>NET Malware</category><category>FSB</category></item><item><title>Chinese Espionage: Google Workspace Rule Abuse in Research Sectors</title><link>https://runtimerebel.com/blog/chinese-espionage-google-workspace-rule-abuse-in-research-sectors</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-espionage-google-workspace-rule-abuse-in-research-sectors</guid><description>China-linked threat actors exploited REDCap server backdoors and manipulated Google Workspace mail rules to exfiltrate North American research data.</description><pubDate>Tue, 16 Jun 2026 01:12:06 GMT</pubDate><category>REDCap</category><category>Google Workspace</category><category>Cyber Espionage</category><category>China</category><category>Data Exfiltration</category></item><item><title>UNC6508: Chinese Cyberespionage Targets North American Research</title><link>https://runtimerebel.com/blog/unc6508-chinese-cyberespionage-targets-north-american-research</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6508-chinese-cyberespionage-targets-north-american-research</guid><description>Google&apos;s Threat Intelligence Group tracks UNC6508, a Chinese cyberespionage group targeting North American medical, military, and AI research sectors.</description><pubDate>Mon, 15 Jun 2026 14:23:41 GMT</pubDate><category>UNC6508</category><category>Cyber Espionage</category><category>China</category><category>APT</category><category>North America</category><category>Medical Research</category><category>Military</category><category>AI Research</category></item><item><title>Iranian Handala Group Claims Cal Water Hack, Exposing PII</title><link>https://runtimerebel.com/blog/iranian-handala-group-claims-cal-water-hack-exposing-pii</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-handala-group-claims-cal-water-hack-exposing-pii</guid><description>Iranian cyber group Handala claims responsibility for breaching Cal Water, exposing 5GB of customer PII and RTKBase platform credentials.</description><pubDate>Fri, 12 Jun 2026 13:21:19 GMT</pubDate><category>Handala</category><category>Cal Water</category><category>Data Breach</category><category>Critical Infrastructure</category><category>RTKBase</category><category>Cyber Espionage</category><category>PII</category></item><item><title>OceanLotus Targets Vietnam with SPECTRALVIPER Backdoor in FireAnt Attack</title><link>https://runtimerebel.com/blog/oceanlotus-targets-vietnam-with-spectralviper-backdoor-in-fireant-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/oceanlotus-targets-vietnam-with-spectralviper-backdoor-in-fireant-attack</guid><description>OceanLotus APT targets Vietnamese infrastructure and stock investors with SPECTRALVIPER backdoor in multi-year cyber espionage and supply chain campaigns.</description><pubDate>Thu, 11 Jun 2026 13:34:13 GMT</pubDate><category>OceanLotus</category><category>APT32</category><category>SPECTRALVIPER</category><category>FireAnt Attack</category><category>Vietnam</category><category>Cyber Espionage</category><category>Supply Chain Attack</category><category>Financial Sector</category></item><item><title>Chinese and North Korean APT Activity Surges Across APAC Markets</title><link>https://runtimerebel.com/blog/chinese-and-north-korean-apt-activity-surges-across-apac-markets</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-and-north-korean-apt-activity-surges-across-apac-markets</guid><description>Chinese and North Korean threat groups are intensifying operations in Asia-Pacific, impacting regional economies and targeting financial institutions for profit.</description><pubDate>Thu, 11 Jun 2026 09:41:37 GMT</pubDate><category>Lazarus Group</category><category>Asia Pacific</category><category>Cyber Espionage</category><category>Financial Crime</category><category>APT</category></item><item><title>Pakistan-Linked Espionage Targets Afghan Finance Ministry via Xeno RAT</title><link>https://runtimerebel.com/blog/pakistan-linked-espionage-targets-afghan-finance-ministry-via-xeno-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/pakistan-linked-espionage-targets-afghan-finance-ministry-via-xeno-rat</guid><description>Analysis of a Pakistan-linked cyber espionage campaign targeting the Afghan Ministry of Finance using the Xeno RAT malware and malicious LNK files.</description><pubDate>Thu, 04 Jun 2026 05:42:02 GMT</pubDate><category>Xeno RAT</category><category>Pakistan</category><category>Afghanistan</category><category>Cyber Espionage</category><category>LNK Malware</category></item><item><title>China-Linked APTs Target Latin American Critical Infrastructure</title><link>https://runtimerebel.com/blog/china-linked-apts-target-latin-american-critical-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-apts-target-latin-american-critical-infrastructure</guid><description>China-linked APTs are conducting widespread cyber espionage against maritime shipping, oil production, and government sectors in Latin America, impacting over a dozen…</description><pubDate>Wed, 03 Jun 2026 21:11:36 GMT</pubDate><category>China Linked APT</category><category>Cyber Espionage</category><category>Latin America</category><category>Critical Infrastructure</category><category>Maritime Shipping</category><category>Oil Production</category></item><item><title>Iranian APT33 Targets Aviation with Updated MimicC2 and PowerLess</title><link>https://runtimerebel.com/blog/iranian-apt33-targets-aviation-with-updated-mimicc2-and-powerless</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-apt33-targets-aviation-with-updated-mimicc2-and-powerless</guid><description>Iranian APT Nimbus Manticore (APT33) targets aviation and software firms using new MimicC2 framework and updated PowerLess tools for stealthy operations.</description><pubDate>Tue, 26 May 2026 20:46:55 GMT</pubDate><category>APT33</category><category>Nimbus Manticore</category><category>Iran</category><category>Aviation</category><category>Software</category><category>MimicC2</category><category>PowerLess</category><category>Cyber Espionage</category><category>Critical Infrastructure</category></item><item><title>MuddyWater Targets South Korean Electronics Maker in Espionage Campaign</title><link>https://runtimerebel.com/blog/muddywater-targets-south-korean-electronics-maker-in-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-targets-south-korean-electronics-maker-in-espionage-campaign</guid><description>Iran-linked MuddyWater (Seedworm) group launched a cyber-espionage campaign against a major South Korean electronics maker and other global entities.</description><pubDate>Thu, 14 May 2026 00:55:56 GMT</pubDate><category>MuddyWater</category><category>Seedworm</category><category>Static Kitten</category><category>Iran</category><category>Cyber Espionage</category><category>South Korea</category><category>Electronics Maker</category><category>APT</category></item><item><title>PamDOORa Backdoor and Windows Phone Link OTP Theft Analysis</title><link>https://runtimerebel.com/blog/pamdoora-backdoor-and-windows-phone-link-otp-theft-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/pamdoora-backdoor-and-windows-phone-link-otp-theft-analysis</guid><description>Recent intelligence highlights the PamDOORa Linux backdoor and malware leveraging Windows Phone Link to bypass OTP-based authentication mechanisms.</description><pubDate>Fri, 08 May 2026 16:37:45 GMT</pubDate><category>PamDOORa</category><category>Linux Backdoor</category><category>Windows Phone Link</category><category>OTP Theft</category><category>Cyber Espionage</category></item><item><title>China-Linked UAT-8302 Targets Governments with Custom APT Malware</title><link>https://runtimerebel.com/blog/china-linked-uat-8302-targets-governments-with-custom-apt-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-uat-8302-targets-governments-with-custom-apt-malware</guid><description>UAT-8302, a China-linked threat group, targets government entities in South America and SE Europe using custom malware and shared APT toolsets.</description><pubDate>Tue, 05 May 2026 16:39:00 GMT</pubDate><category>UAT 8302</category><category>China</category><category>APT</category><category>Cisco Talos</category><category>Cyber Espionage</category></item><item><title>Alleged Silk Typhoon Hacker Extradited: Cyberespionage Threat</title><link>https://runtimerebel.com/blog/alleged-silk-typhoon-hacker-extradited-cyberespionage-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/alleged-silk-typhoon-hacker-extradited-cyberespionage-threat</guid><description>An alleged Silk Typhoon hacker, associated with Chinese intelligence, has been extradited to the US, highlighting persistent nation-state cyberespionage threats.</description><pubDate>Mon, 27 Apr 2026 20:30:07 GMT</pubDate><category>Silk Typhoon</category><category>Volt Typhoon</category><category>Cyber Espionage</category><category>Nation State</category><category>China</category><category>Extradition</category><category>APT</category></item><item><title>Chinese State-Backed Actors Industrialize Botnets for Covert Ops</title><link>https://runtimerebel.com/blog/chinese-state-backed-actors-industrialize-botnets-for-covert-ops</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-state-backed-actors-industrialize-botnets-for-covert-ops</guid><description>Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.</description><pubDate>Fri, 24 Apr 2026 00:47:01 GMT</pubDate><category>China</category><category>State Backed</category><category>Botnet</category><category>APT</category><category>Cyber Espionage</category><category>Industrialized Botnets</category></item><item><title>Chinese APT Targeting Indian Banks and Korean Policy Circles</title><link>https://runtimerebel.com/blog/chinese-apt-targeting-indian-banks-and-korean-policy-circles</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-apt-targeting-indian-banks-and-korean-policy-circles</guid><description>Chinese state-sponsored threat actors are conducting cyber-espionage against Indian financial institutions and South Korean policy entities using recycled TTPs.</description><pubDate>Tue, 21 Apr 2026 12:33:56 GMT</pubDate><category>Chinese APT</category><category>India Banking</category><category>South Korea</category><category>Cyber Espionage</category><category>Financial Sector</category></item><item><title>APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers</title><link>https://runtimerebel.com/blog/apt28-forest-blizzard-dns-manipulation-targets-soho-routers</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-forest-blizzard-dns-manipulation-targets-soho-routers</guid><description>Russian APT28, or Forest Blizzard, is conducting malwareless cyber espionage by manipulating DNS settings on vulnerable SOHO routers to steal credentials from global…</description><pubDate>Thu, 09 Apr 2026 04:53:01 GMT</pubDate><category>APT28</category><category>Forest Blizzard</category><category>SOHO Routers</category><category>DNS Manipulation</category><category>Credential Theft</category><category>Cyber Espionage</category><category>Nation State</category></item><item><title>APT28 Exploits MikroTik &amp; TP-Link Routers in DNS Hijacking</title><link>https://runtimerebel.com/blog/apt28-exploits-mikrotik-tp-link-routers-in-dns-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-exploits-mikrotik-tp-link-routers-in-dns-hijacking</guid><description>Russian state-linked APT28 (Forest Blizzard) is compromising insecure SOHO routers globally, employing DNS hijacking for cyber espionage since May 2025.</description><pubDate>Tue, 07 Apr 2026 20:18:04 GMT</pubDate><category>APT28</category><category>Forest Blizzard</category><category>SOHO Routers</category><category>MikroTik</category><category>TP Link</category><category>DNS Hijacking</category><category>Cyber Espionage</category></item><item><title>Pro-Iranian Group Claims Hack of FBI Director&apos;s Personal Account</title><link>https://runtimerebel.com/blog/pro-iranian-group-claims-hack-of-fbi-director-s-personal-account</link><guid isPermaLink="true">https://runtimerebel.com/blog/pro-iranian-group-claims-hack-of-fbi-director-s-personal-account</guid><description>A pro-Iranian hacking group claims to have compromised the personal account of FBI Director Kash Patel, exfiltrating emails and documents.</description><pubDate>Fri, 27 Mar 2026 20:15:51 GMT</pubDate><category>Pro Iranian Hacking Group</category><category>Kash Patel</category><category>FBI</category><category>Account Compromise</category><category>Cyber Espionage</category><category>Geopolitical</category></item><item><title>Earth Kaluu Cyberespionage Campaign Targets SE Asian Military Orgs</title><link>https://runtimerebel.com/blog/earth-kaluu-cyberespionage-campaign-targets-se-asian-military-orgs</link><guid isPermaLink="true">https://runtimerebel.com/blog/earth-kaluu-cyberespionage-campaign-targets-se-asian-military-orgs</guid><description>An investigation into the China-nexus Earth Kaluu campaign reveals long-term persistence in Southeast Asian military networks using custom backdoors.</description><pubDate>Tue, 17 Mar 2026 04:40:49 GMT</pubDate><category>Earth Kaluu</category><category>Mustang Panda</category><category>Southeast Asia</category><category>Cyber Espionage</category><category>DLL Side Loading</category></item><item><title>CL-STA-1087: Chinese Hackers Target SE Asian Military with AppleChris</title><link>https://runtimerebel.com/blog/cl-sta-1087-chinese-hackers-target-se-asian-military-with-applechris</link><guid isPermaLink="true">https://runtimerebel.com/blog/cl-sta-1087-chinese-hackers-target-se-asian-military-with-applechris</guid><description>Chinese threat actor CL-STA-1087 leverages AppleChris and MemFun malware to target Southeast Asian military organizations in long-term espionage campaigns.</description><pubDate>Fri, 13 Mar 2026 20:12:54 GMT</pubDate><category>CL STA 1087</category><category>AppleChris</category><category>MemFun</category><category>Unit 42</category><category>Southeast Asia</category><category>Cyber Espionage</category></item><item><title>Nation-State Cyber Operation: Israel&apos;s Compromise of Iranian Traffic Cameras</title><link>https://runtimerebel.com/blog/nation-state-cyber-operation-israel-s-compromise-of-iranian-traffic-cameras</link><guid isPermaLink="true">https://runtimerebel.com/blog/nation-state-cyber-operation-israel-s-compromise-of-iranian-traffic-cameras</guid><description>Analysis of the reported Israeli cyber operation targeting Iranian traffic cameras, detailing implications for critical infrastructure security and cyber-physical…</description><pubDate>Thu, 05 Mar 2026 20:17:25 GMT</pubDate><category>Israel</category><category>Iran</category><category>Traffic Cameras</category><category>Cyber Espionage</category><category>Nation State Attack</category><category>Critical Infrastructure</category><category>OT Security</category></item><item><title>Chinese Police Use ChatGPT in Influence Operations Against Japan</title><link>https://runtimerebel.com/blog/chinese-police-use-chatgpt-in-influence-operations-against-japan</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-police-use-chatgpt-in-influence-operations-against-japan</guid><description>Chinese police reportedly used ChatGPT for politically motivated influence operations to smear Japan&apos;s PM Takaichi, highlighting AI&apos;s role in disinformation campaigns.</description><pubDate>Thu, 26 Feb 2026 00:33:49 GMT</pubDate><category>ChatGPT</category><category>Influence Operations</category><category>Disinformation</category><category>Nation State</category><category>China</category><category>Japan</category><category>AI</category><category>Cyber Espionage</category></item><item><title>GRIDTIDE Espionage: PRC-Nexus UNC2814 Targets Telecoms Globally</title><link>https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</link><guid isPermaLink="true">https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</guid><description>Google disrupts GRIDTIDE, a novel backdoor used by PRC-nexus UNC2814 for global cyber espionage against telecommunications and government entities.</description><pubDate>Wed, 25 Feb 2026 16:34:59 GMT</pubDate><category>UNC2814</category><category>GRIDTIDE</category><category>PRC Nexus</category><category>Cyber Espionage</category><category>Telecommunications</category><category>Government</category><category>Google Sheets API</category><category>SoftEther VPN</category><category>C2</category><category>Linux Malware</category><category>TTPs</category></item><item><title>Google Disrupts Chinese Espionage Actor UNC2814 Targeting Telecoms</title><link>https://runtimerebel.com/blog/google-disrupts-chinese-espionage-actor-unc2814-targeting-telecoms</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-disrupts-chinese-espionage-actor-unc2814-targeting-telecoms</guid><description>Google and Mandiant disrupt UNC2814, a Chinese state-sponsored actor active since 2017, targeting 42 countries across telecom and government sectors.</description><pubDate>Wed, 25 Feb 2026 16:34:10 GMT</pubDate><category>UNC2814</category><category>China</category><category>Cyber Espionage</category><category>Google TAG</category><category>Mandiant</category><category>Telecommunications</category><category>State Sponsored</category></item><item><title>US Treasury Sanctions Russian Broker for Stolen Zero-Day Exploits</title><link>https://runtimerebel.com/blog/us-treasury-sanctions-russian-broker-for-stolen-zero-day-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-treasury-sanctions-russian-broker-for-stolen-zero-day-exploits</guid><description>The US sanctions Artem Kruglov and associated firms for brokering stolen hacking tools and zero-day exploits for Russian intelligence services.</description><pubDate>Wed, 25 Feb 2026 12:24:10 GMT</pubDate><category>OFAC</category><category>Sanctions</category><category>Zero-Day</category><category>Artem Kruglov</category><category>Russia</category><category>Cyber Espionage</category><category>SVR</category></item><item><title>MuddyWater Deploys BugSleep Backdoor in Targeted Regional Campaigns</title><link>https://runtimerebel.com/blog/muddywater-deploys-bugsleep-backdoor-in-targeted-regional-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-deploys-bugsleep-backdoor-in-targeted-regional-campaigns</guid><description>Iranian state actor MuddyWater introduces the custom BugSleep backdoor, targeting Middle Eastern and African entities using spear-phishing and RMM abuse.</description><pubDate>Tue, 24 Feb 2026 08:22:38 GMT</pubDate><category>MuddyWater</category><category>BugSleep</category><category>MOIS</category><category>Spear Phishing</category><category>RMM Abuse</category><category>Iran</category><category>Cyber Espionage</category></item></channel></rss>