<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Espionage</title><description>Cybersecurity articles tagged #Espionage on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>SilkParasite Espionage Campaign Targets Central Asian Governments</title><link>https://runtimerebel.com/blog/silkparasite-espionage-campaign-targets-central-asian-governments</link><guid isPermaLink="true">https://runtimerebel.com/blog/silkparasite-espionage-campaign-targets-central-asian-governments</guid><description>SilkParasite espionage campaign targets Central Asian governments with seven remote access tools, including five newly documented RAT families.</description><pubDate>Wed, 19 Aug 2026 16:20:56 GMT</pubDate><category>Espionage</category><category>RAT</category><category>Malware</category><category>SilkParasite</category><category>ShadowPad</category></item><item><title>Suspected Chinese-Speaking Hackers Deploy OctLurk, SilkLurk Backdoors</title><link>https://runtimerebel.com/blog/suspected-chinese-speaking-hackers-deploy-octlurk-silklurk-backdoors</link><guid isPermaLink="true">https://runtimerebel.com/blog/suspected-chinese-speaking-hackers-deploy-octlurk-silklurk-backdoors</guid><description>Ongoing cyberattacks by a suspected Chinese-speaking threat actor target Central Asian governments with OctLurk and SilkLurk backdoors for espionage and data theft.</description><pubDate>Sat, 01 Aug 2026 02:54:42 GMT</pubDate><category>Chinese Speaking Hackers</category><category>OctLurk</category><category>SilLurk</category><category>Central Asia</category><category>Government Targets</category><category>Espionage</category><category>Backdoor</category></item><item><title>US Humanoid Robot Ban: Mitigating Chinese Supply Chain Risks</title><link>https://runtimerebel.com/blog/us-humanoid-robot-ban-mitigating-chinese-supply-chain-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-humanoid-robot-ban-mitigating-chinese-supply-chain-risks</guid><description>The U.S. ban on foreign-made humanoid robots highlights growing concerns over data exfiltration and national security risks linked to Chinese manufacturing.</description><pubDate>Wed, 29 Jul 2026 14:14:03 GMT</pubDate><category>China</category><category>Supply Chain</category><category>National Security</category><category>Robotics</category><category>Espionage</category></item><item><title>AI Agent Espionage Against Thai Ministry of Finance: Hermes YOLO Mode</title><link>https://runtimerebel.com/blog/ai-agent-espionage-against-thai-ministry-of-finance-hermes-yolo-mode</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-espionage-against-thai-ministry-of-finance-hermes-yolo-mode</guid><description>Attackers leveraged the Hermes AI agent in &apos;YOLO mode&apos; to perform an espionage operation targeting Thailand&apos;s Ministry of Finance. Learn TTPs and defense.</description><pubDate>Tue, 28 Jul 2026 02:39:41 GMT</pubDate><category>Hermes AI Agent</category><category>Espionage</category><category>YOLO Mode</category><category>Thai Ministry of Finance</category><category>Nation State Threat</category><category>Autonomous AI</category></item><item><title>HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2</title><link>https://runtimerebel.com/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/hollowgraph-malware-leverages-microsoft-365-calendar-for-stealthy-c2</guid><description>HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.</description><pubDate>Mon, 20 Jul 2026 18:05:24 GMT</pubDate><category>HollowGraph</category><category>Microsoft 365</category><category>Microsoft Graph API</category><category>Espionage</category><category>C2</category><category>Data Exfiltration</category><category>Group IB</category></item><item><title>Balochistan Police Portal Exploited in Multi-Group Espionage Campaign</title><link>https://runtimerebel.com/blog/balochistan-police-portal-exploited-in-multi-group-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/balochistan-police-portal-exploited-in-multi-group-espionage-campaign</guid><description>Multiple threat actors weaponize Balochistan Police infrastructure, compromising criminal records and citizen data in a multi-year espionage operation.</description><pubDate>Sat, 11 Jul 2026 20:51:09 GMT</pubDate><category>Balochistan Police</category><category>Pakistan</category><category>Espionage</category><category>Data Breach</category><category>Law Enforcement</category></item><item><title>Roundcube Flaw Exploited by China-Linked Group Against Academics</title><link>https://runtimerebel.com/blog/roundcube-flaw-exploited-by-china-linked-group-against-academics</link><guid isPermaLink="true">https://runtimerebel.com/blog/roundcube-flaw-exploited-by-china-linked-group-against-academics</guid><description>A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.</description><pubDate>Wed, 08 Jul 2026 21:35:37 GMT</pubDate><category>Roundcube</category><category>Academic Sector</category><category>Credential Theft</category><category>Backdoor</category><category>China Linked</category><category>Espionage</category><category>Universities</category></item><item><title>Google Disrupts NetNut Malicious Residential Proxy Network</title><link>https://runtimerebel.com/blog/google-disrupts-netnut-malicious-residential-proxy-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-disrupts-netnut-malicious-residential-proxy-network</guid><description>Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.</description><pubDate>Fri, 03 Jul 2026 07:31:53 GMT</pubDate><category>NetNut</category><category>Residential Proxy</category><category>Botnet</category><category>C2</category><category>Google Play Protect</category><category>Malware</category><category>IPIDEA</category><category>Cybercrime</category><category>Espionage</category></item><item><title>China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor</title><link>https://runtimerebel.com/blog/china-linked-apt-targets-southeast-asia-critical-systems-with-new-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-apt-targets-southeast-asia-critical-systems-with-new-backdoor</guid><description>A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.</description><pubDate>Wed, 01 Jul 2026 05:41:17 GMT</pubDate><category>China Linked APT</category><category>Southeast Asia</category><category>Critical Infrastructure</category><category>Backdoor</category><category>State Sponsored</category><category>Espionage</category><category>Cyber Warfare</category></item><item><title>Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks</title><link>https://runtimerebel.com/blog/mustang-panda-exploits-zoho-workdrive-for-c2-in-indian-govt-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/mustang-panda-exploits-zoho-workdrive-for-c2-in-indian-govt-attacks</guid><description>Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.</description><pubDate>Mon, 29 Jun 2026 17:06:24 GMT</pubDate><category>Mustang Panda</category><category>APT</category><category>Zoho WorkDrive</category><category>Indian Government</category><category>Espionage</category><category>C2</category><category>Cloud Security</category></item><item><title>UNC5792 &amp; UNC4221 Target US Officials via Messaging Apps</title><link>https://runtimerebel.com/blog/unc5792-unc4221-target-us-officials-via-messaging-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc5792-unc4221-target-us-officials-via-messaging-apps</guid><description>Russian state-linked groups UNC5792 and UNC4221 are actively targeting US government, military, and allied personnel through evolving messaging app attacks.</description><pubDate>Mon, 29 Jun 2026 10:10:24 GMT</pubDate><category>UNC5792</category><category>UNC4221</category><category>Russian APT</category><category>Messaging App Attacks</category><category>Government Targeting</category><category>Espionage</category><category>Mobile Security</category></item><item><title>Turla APT Deploys StockStay Backdoor in Ukraine Espionage Campaign</title><link>https://runtimerebel.com/blog/turla-apt-deploys-stockstay-backdoor-in-ukraine-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/turla-apt-deploys-stockstay-backdoor-in-ukraine-espionage-campaign</guid><description>Russian APT Turla targets Ukrainian government and military entities with the custom StockStay backdoor for persistent access and cyber espionage.</description><pubDate>Fri, 26 Jun 2026 09:18:02 GMT</pubDate><category>Turla</category><category>STOCKSTAY</category><category>Ukraine</category><category>Espionage</category><category>Russian APT</category><category>Malware</category></item><item><title>Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations</title><link>https://runtimerebel.com/blog/turla-deploys-new-stockstay-backdoor-in-ukraine-espionage-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/turla-deploys-new-stockstay-backdoor-in-ukraine-espionage-operations</guid><description>Google identifies STOCKSTAY, a new .NET backdoor by Russian actor Turla targeting Ukrainian military and Italian foreign policy interests via Windows systems.</description><pubDate>Fri, 26 Jun 2026 09:17:20 GMT</pubDate><category>Turla</category><category>STOCKSTAY</category><category>Ukraine</category><category>Espionage</category><category>TAG 70</category><category>KRYPTON</category><category>NET</category></item><item><title>UNC6508 Targets REDCap Servers: Espionage via INFINITERED Malware</title><link>https://runtimerebel.com/blog/unc6508-targets-redcap-servers-espionage-via-infinitered-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6508-targets-redcap-servers-espionage-via-infinitered-malware</guid><description>PRC-nexus threat actor UNC6508 exploits REDCap servers in North America&apos;s medical and military research sectors, deploying INFINITERED malware for long-term espionage…</description><pubDate>Mon, 15 Jun 2026 17:51:05 GMT</pubDate><category>UNC6508</category><category>INFINITERED</category><category>REDCap</category><category>PRC Nexus</category><category>Espionage</category><category>Medical Research</category><category>Military Research</category></item><item><title>China-Nexus Actor: Year-Long Espionage Against US Researchers</title><link>https://runtimerebel.com/blog/china-nexus-actor-year-long-espionage-against-us-researchers</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-nexus-actor-year-long-espionage-against-us-researchers</guid><description>A China-nexus actor spied on US researchers for a year, stealing RedCAP credentials and exfiltrating sensitive data from numerous institutions, discovered by Google.</description><pubDate>Mon, 15 Jun 2026 17:49:38 GMT</pubDate><category>China Nexus Actor</category><category>Espionage</category><category>US Researchers</category><category>RedCAP Credentials</category><category>Data Exfiltration</category><category>Nation State Threat</category></item><item><title>China-Linked Espionage Targets REDCap Servers, Stealing Medical Data</title><link>https://runtimerebel.com/blog/china-linked-espionage-targets-redcap-servers-stealing-medical-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-espionage-targets-redcap-servers-stealing-medical-data</guid><description>China-linked threat actors breached exposed REDCap servers, deploying InfiniteRed malware to steal sensitive medical research from a North American institution.</description><pubDate>Mon, 15 Jun 2026 14:23:10 GMT</pubDate><category>China Linked</category><category>REDCap</category><category>INFINITERED</category><category>Medical Sector</category><category>Data Breach</category><category>Espionage</category></item><item><title>Chinese Hackers Hijack Auth Flow for Decade-Long Espionage</title><link>https://runtimerebel.com/blog/chinese-hackers-hijack-auth-flow-for-decade-long-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-hackers-hijack-auth-flow-for-decade-long-espionage</guid><description>Chinese state-sponsored hackers maintained long-term access to an isolated network by hijacking the authentication flow, enabling a decade of espionage.</description><pubDate>Sat, 13 Jun 2026 16:36:15 GMT</pubDate><category>Chinese Hackers</category><category>Authentication Bypass</category><category>Long Term Persistence</category><category>Espionage</category><category>Isolated Network</category><category>APT</category></item><item><title>Chinese APT UNC5221 Deploys New Malware for M365 Persistence</title><link>https://runtimerebel.com/blog/chinese-apt-unc5221-deploys-new-malware-for-m365-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-apt-unc5221-deploys-new-malware-for-m365-persistence</guid><description>Chinese APT UNC5221 leverages new malware, Plenet and AgentPSD, alongside Brickstorm backdoor to maintain persistent access in compromised Microsoft 365 environments for…</description><pubDate>Fri, 05 Jun 2026 20:41:36 GMT</pubDate><category>UNC5221</category><category>Microsoft 365</category><category>BRICKSTORM</category><category>Plenet</category><category>AgentPSD</category><category>APT</category><category>Espionage</category></item><item><title>OP-512: Analyzing the Custom Web Shell Framework Targeting Microsoft IIS</title><link>https://runtimerebel.com/blog/op-512-analyzing-the-custom-web-shell-framework-targeting-microsoft-iis</link><guid isPermaLink="true">https://runtimerebel.com/blog/op-512-analyzing-the-custom-web-shell-framework-targeting-microsoft-iis</guid><description>Security researchers have identified OP-512, a China-nexus threat cluster targeting Microsoft IIS servers with a bespoke web shell framework for espionage.</description><pubDate>Fri, 05 Jun 2026 16:54:33 GMT</pubDate><category>OP 512</category><category>Microsoft IIS</category><category>Webshell</category><category>Espionage</category><category>China Nexus</category></item><item><title>Handala Brand Evolution: Iran MOIS Shifts to Hybrid Physical Attacks</title><link>https://runtimerebel.com/blog/handala-brand-evolution-iran-mois-shifts-to-hybrid-physical-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/handala-brand-evolution-iran-mois-shifts-to-hybrid-physical-attacks</guid><description>Iran’s MOIS expands the Handala brand into hybrid operations, combining cyber espionage with physical sabotage targeting U.S. and Israeli interests.</description><pubDate>Tue, 02 Jun 2026 17:39:53 GMT</pubDate><category>Handala</category><category>MOIS</category><category>Iran</category><category>Cyber Physical</category><category>Espionage</category><category>Israel</category><category>Proxy Warfare</category></item><item><title>MuddyWater 2026 Espionage: DLL Side-Loading Across 9 Countries</title><link>https://runtimerebel.com/blog/muddywater-2026-espionage-dll-side-loading-across-9-countries</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-2026-espionage-dll-side-loading-across-9-countries</guid><description>Iranian group MuddyWater targets industrial manufacturing and financial sectors in a global 2026 espionage campaign using DLL side-loading techniques.</description><pubDate>Tue, 26 May 2026 17:14:39 GMT</pubDate><category>MuddyWater</category><category>APT33</category><category>DLL Side Loading</category><category>Espionage</category><category>Iran</category></item><item><title>FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing</title><link>https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</guid><description>Belarussian APT &apos;FrostyNeighbor&apos; is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…</description><pubDate>Thu, 14 May 2026 20:38:13 GMT</pubDate><category>FrostyNeighbor</category><category>APT</category><category>Belarus</category><category>Poland</category><category>Ukraine</category><category>Espionage</category><category>Spear Phishing</category><category>Government</category><category>Nation State</category></item><item><title>YoroTrooper Campaign Hits 500+ Orgs: Espionage and Malware Tactics</title><link>https://runtimerebel.com/blog/yorotrooper-campaign-hits-500-orgs-espionage-and-malware-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/yorotrooper-campaign-hits-500-orgs-espionage-and-malware-tactics</guid><description>Analysis of the multi-year YoroTrooper phishing campaign targeting critical infrastructure, aviation, and government sectors with custom malware stealers.</description><pubDate>Mon, 11 May 2026 05:25:02 GMT</pubDate><category>YoroTrooper</category><category>Espionage</category><category>Stink Stealer</category><category>Critical Infrastructure</category><category>Phishing</category></item><item><title>SHADOW-EARTH-053: China-Linked APT Targets NATO and Asian Governments</title><link>https://runtimerebel.com/blog/shadow-earth-053-china-linked-apt-targets-nato-and-asian-governments</link><guid isPermaLink="true">https://runtimerebel.com/blog/shadow-earth-053-china-linked-apt-targets-nato-and-asian-governments</guid><description>Trend Micro uncovers SHADOW-EARTH-053, a China-aligned espionage group targeting defense sectors in Asia and a NATO member through advanced TTPs.</description><pubDate>Fri, 01 May 2026 16:26:03 GMT</pubDate><category>SHADOW EARTH 053</category><category>China Aligned</category><category>Espionage</category><category>NATO</category><category>South Asia</category></item><item><title>Tropic Trooper APT Targets Home Routers and Japanese Infrastructure</title><link>https://runtimerebel.com/blog/tropic-trooper-apt-targets-home-routers-and-japanese-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/tropic-trooper-apt-targets-home-routers-and-japanese-infrastructure</guid><description>Tropic Trooper expands operations to target Japanese entities and home routers using specialized malware like Chinoiserie to obfuscate attack origins.</description><pubDate>Fri, 24 Apr 2026 05:07:08 GMT</pubDate><category>Tropic Trooper</category><category>Key Boy</category><category>Japan</category><category>SOHO</category><category>Chinoiserie</category><category>Espionage</category></item><item><title>Chinese APT Leverages PlugX &amp; ShadowPad with Cloud C2 for Mongolian Espionage</title><link>https://runtimerebel.com/blog/chinese-apt-leverages-plugx-shadowpad-with-cloud-c2-for-mongolian-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-apt-leverages-plugx-shadowpad-with-cloud-c2-for-mongolian-espionage</guid><description>A Chinese state-sponsored APT is exploiting Microsoft Outlook, Slack, Discord, and file.io for C2, deploying PlugX and ShadowPad in espionage operations targeting…</description><pubDate>Thu, 23 Apr 2026 16:42:54 GMT</pubDate><category>Chinese APT</category><category>Cloud Security</category><category>Espionage</category><category>Mongolia</category><category>Command and Control</category><category>Microsoft Outlook</category><category>Slack</category><category>Discord</category><category>File Io</category><category>PlugX</category><category>ShadowPad</category><category>DLL Side Loading</category><category>Phishing</category></item><item><title>Mustang Panda Targets Indian Banks with New LOTUSLITE Variant</title><link>https://runtimerebel.com/blog/mustang-panda-targets-indian-banks-with-new-lotuslite-variant</link><guid isPermaLink="true">https://runtimerebel.com/blog/mustang-panda-targets-indian-banks-with-new-lotuslite-variant</guid><description>Mustang Panda deploys a new LOTUSLITE malware variant against Indian financial institutions and South Korean policy entities for cyber espionage operations.</description><pubDate>Wed, 22 Apr 2026 08:41:58 GMT</pubDate><category>Mustang Panda</category><category>Lotuslite</category><category>Espionage</category><category>Financial Sector</category><category>South Korea</category></item><item><title>Russian Hackers Exploit Routers to Steal Microsoft Office Tokens</title><link>https://runtimerebel.com/blog/russian-hackers-exploit-routers-to-steal-microsoft-office-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-hackers-exploit-routers-to-steal-microsoft-office-tokens</guid><description>Russian military intelligence-linked hackers exploited known router flaws to harvest Microsoft Office authentication tokens from over 18,000 networks, posing a…</description><pubDate>Tue, 07 Apr 2026 20:19:57 GMT</pubDate><category>Russia</category><category>Military Intelligence</category><category>Router Security</category><category>Microsoft Office</category><category>Authentication Tokens</category><category>Nation State</category><category>Espionage</category></item><item><title>BRICKSTORM Malware: Hardening vSphere &amp; VCSA Against Advanced Threats</title><link>https://runtimerebel.com/blog/brickstorm-malware-hardening-vsphere-vcsa-against-advanced-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/brickstorm-malware-hardening-vsphere-vcsa-against-advanced-threats</guid><description>Defend VMware vSphere and VCSA against BRICKSTORM malware. Learn hardening strategies, identity management, Zero Trust networking, and advanced logging to thwart…</description><pubDate>Thu, 02 Apr 2026 16:29:31 GMT</pubDate><category>BRICKSTORM</category><category>vSphere</category><category>VCSA</category><category>ESXi</category><category>VMware</category><category>Photon OS</category><category>Hardening</category><category>Virtualization</category><category>TTPs</category><category>Ransomware</category><category>Espionage</category><category>CVE-2021-21972</category><category>Mandiant</category></item><item><title>Iranian-Linked Handala Group Breaches Kash Patel&apos;s Personal Email</title><link>https://runtimerebel.com/blog/iranian-linked-handala-group-breaches-kash-patel-s-personal-email</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-linked-handala-group-breaches-kash-patel-s-personal-email</guid><description>FBI confirms Iranian-linked Handala hackers breached Director nominee Kash Patel&apos;s personal email, leaking documents and highlighting spear-phishing risks.</description><pubDate>Mon, 30 Mar 2026 00:41:00 GMT</pubDate><category>Handala</category><category>Iran</category><category>Kash Patel</category><category>FBI</category><category>Spear Phishing</category><category>Espionage</category></item><item><title>Red Menshen APT Deploys Upgraded BPFdoor Backdoor Against Telcos</title><link>https://runtimerebel.com/blog/red-menshen-apt-deploys-upgraded-bpfdoor-backdoor-against-telcos</link><guid isPermaLink="true">https://runtimerebel.com/blog/red-menshen-apt-deploys-upgraded-bpfdoor-backdoor-against-telcos</guid><description>Chinese APT Red Menshen utilizes an upgraded BPFdoor backdoor to target global telecommunication companies, bypassing traditional defenses.</description><pubDate>Fri, 27 Mar 2026 20:16:14 GMT</pubDate><category>Red Menshen</category><category>BPFdoor</category><category>APT</category><category>Telecommunications</category><category>China</category><category>Backdoor</category><category>Espionage</category></item><item><title>Red Menshen BPFDoor Implants Target Telecom Networks for Espionage</title><link>https://runtimerebel.com/blog/red-menshen-bpfdoor-implants-target-telecom-networks-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/red-menshen-bpfdoor-implants-target-telecom-networks-for-espionage</guid><description>Analysis of China-linked Red Menshen&apos;s long-term campaign using stealthy BPFDoor implants within telecom networks to conduct espionage against government entities.</description><pubDate>Thu, 26 Mar 2026 20:14:16 GMT</pubDate><category>Red Menshen</category><category>Earth Bluecrow</category><category>BPFdoor</category><category>Telecom</category><category>Espionage</category><category>China Nexus</category><category>APT</category></item><item><title>M-Trends 2026: Evolving Ransomware, Persistence, and SaaS Attack Vectors</title><link>https://runtimerebel.com/blog/m-trends-2026-evolving-ransomware-persistence-and-saas-attack-vectors</link><guid isPermaLink="true">https://runtimerebel.com/blog/m-trends-2026-evolving-ransomware-persistence-and-saas-attack-vectors</guid><description>M-Trends 2026 reveals critical shifts in adversary TTPs: destructive ransomware, zero-day exploitation for persistence, and voice phishing for SaaS access.</description><pubDate>Mon, 23 Mar 2026 16:28:06 GMT</pubDate><category>M Trends 2026</category><category>Ransomware</category><category>Espionage</category><category>Voice Phishing</category><category>SaaS Security</category><category>Zero-Day</category><category>Edge Devices</category><category>UNC3944</category><category>REDBIKE</category><category>AGENDA</category><category>BRICKSTORM</category><category>PROMPTFLUX</category><category>AI Security</category></item><item><title>DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users</title><link>https://runtimerebel.com/blog/darksword-iphone-exploit-kit-zero-day-attacks-on-ios-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/darksword-iphone-exploit-kit-zero-day-attacks-on-ios-users</guid><description>DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…</description><pubDate>Thu, 19 Mar 2026 00:37:39 GMT</pubDate><category>DarkSword</category><category>iOS</category><category>iPhone</category><category>Zero-Day</category><category>Exploit Kit</category><category>Nation State</category><category>Cybercrime</category><category>Espionage</category><category>Turkey</category><category>Saudi Arabia</category><category>Malaysia</category><category>Ukraine</category></item><item><title>Chinese Nexus Actors Pivot to Qatar: Geopolitical Espionage</title><link>https://runtimerebel.com/blog/chinese-nexus-actors-pivot-to-qatar-geopolitical-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-nexus-actors-pivot-to-qatar-geopolitical-espionage</guid><description>Analysis of Chinese Nexus actors&apos; shift to targeting Qatari entities amid Iranian conflict. Understand their adaptable TTPs and fortify defenses.</description><pubDate>Wed, 11 Mar 2026 16:31:22 GMT</pubDate><category>Chinese Nexus Actors</category><category>Qatar</category><category>Iran</category><category>Geopolitics</category><category>Espionage</category><category>Nation State APT</category></item><item><title>Chinese Cyber Threat: Persistent Espionage in Critical Asian Sectors</title><link>https://runtimerebel.com/blog/chinese-cyber-threat-persistent-espionage-in-critical-asian-sectors</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-cyber-threat-persistent-espionage-in-critical-asian-sectors</guid><description>An undefined Chinese-speaking actor conducts long-term cyber espionage against critical Asian sectors using custom malware and living-off-the-land binaries.</description><pubDate>Mon, 09 Mar 2026 16:35:16 GMT</pubDate><category>Chinese APT</category><category>Espionage</category><category>Windows</category><category>Linux</category><category>LOTL</category><category>Custom Malware</category><category>Critical Infrastructure</category><category>Threat Actor</category></item><item><title>Coruna iOS Exploit Kit: Spyware-Grade Threat Targets Crypto</title><link>https://runtimerebel.com/blog/coruna-ios-exploit-kit-spyware-grade-threat-targets-crypto</link><guid isPermaLink="true">https://runtimerebel.com/blog/coruna-ios-exploit-kit-spyware-grade-threat-targets-crypto</guid><description>The sophisticated Coruna iOS exploit kit, leveraging 23 undocumented vulnerabilities, is now deployed in targeted espionage and crypto theft attacks.</description><pubDate>Wed, 04 Mar 2026 20:15:16 GMT</pubDate><category>Coruna</category><category>iOS</category><category>Exploit Kit</category><category>Mobile Security</category><category>Crypto Theft</category><category>Espionage</category><category>Zero-Day</category></item><item><title>Chinese Cyberspies Exploit SaaS APIs in Global Espionage Campaign</title><link>https://runtimerebel.com/blog/chinese-cyberspies-exploit-saas-apis-in-global-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-cyberspies-exploit-saas-apis-in-global-espionage-campaign</guid><description>A suspected Chinese threat actor breached dozens of telecom firms and government agencies, using SaaS API calls to evade detection in a global espionage campaign.</description><pubDate>Wed, 25 Feb 2026 20:16:16 GMT</pubDate><category>Chinese Threat Actor</category><category>Espionage</category><category>SaaS API Abuse</category><category>Telecom</category><category>Government</category><category>Mandiant</category><category>Google GTIG</category></item><item><title>Google Disrupts UNC2814 GRIDTIDE Infrastructure After 53 Breaches</title><link>https://runtimerebel.com/blog/google-disrupts-unc2814-gridtide-infrastructure-after-53-breaches</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-disrupts-unc2814-gridtide-infrastructure-after-53-breaches</guid><description>Google disrupts infrastructure of China-nexus threat actor UNC2814 (GRIDTIDE) after 53 breaches across 42 countries targeting government and telecom sectors.</description><pubDate>Wed, 25 Feb 2026 20:15:13 GMT</pubDate><category>UNC2814</category><category>GRIDTIDE</category><category>China Nexus</category><category>APT</category><category>Telecommunications</category><category>Espionage</category></item><item><title>Ex-L3Harris Executive Sentenced for Selling Zero-Days to Russia</title><link>https://runtimerebel.com/blog/ex-l3harris-executive-sentenced-for-selling-zero-days-to-russia</link><guid isPermaLink="true">https://runtimerebel.com/blog/ex-l3harris-executive-sentenced-for-selling-zero-days-to-russia</guid><description>Former Trenchant CEO James Michael Robinson sentenced to 90 months for stealing zero-day exploits and selling them to a Russian state-linked broker.</description><pubDate>Wed, 25 Feb 2026 12:25:01 GMT</pubDate><category>L3Harris</category><category>Trenchant</category><category>Zero-Day</category><category>Insider Threat</category><category>Russia</category><category>Espionage</category><category>Cyber Exploits</category></item><item><title>L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker</title><link>https://runtimerebel.com/blog/l3harris-insider-sentenced-for-selling-zero-days-to-russian-broker</link><guid isPermaLink="true">https://runtimerebel.com/blog/l3harris-insider-sentenced-for-selling-zero-days-to-russian-broker</guid><description>Former defense contractor Peter Williams sentenced to seven years for selling eight zero-day exploits to Russian broker Operation Zero for millions in profit.</description><pubDate>Wed, 25 Feb 2026 12:22:37 GMT</pubDate><category>Insider Threat</category><category>Zero-Day</category><category>Operation Zero</category><category>L3Harris</category><category>Espionage</category><category>Trade Secrets</category></item><item><title>UAC-0050 Targets European Financial Institutions with RMS Malware</title><link>https://runtimerebel.com/blog/uac-0050-targets-european-financial-institutions-with-rms-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uac-0050-targets-european-financial-institutions-with-rms-malware</guid><description>Russia-aligned actor UAC-0050 expands operations beyond Ukraine, targeting European financial entities with spoofed domains and RMS malware for espionage.</description><pubDate>Wed, 25 Feb 2026 00:37:36 GMT</pubDate><category>UAC 0050</category><category>RMS Malware</category><category>Phishing</category><category>Financial Sector</category><category>Espionage</category></item><item><title>UnsolicitedBooker Targets Central Asian Telecoms via LuciDoor Backdoor</title><link>https://runtimerebel.com/blog/unsolicitedbooker-targets-central-asian-telecoms-via-lucidoor-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/unsolicitedbooker-targets-central-asian-telecoms-via-lucidoor-backdoor</guid><description>The UnsolicitedBooker threat actor has pivoted to targeting telecommunications providers in Kyrgyzstan and Tajikistan using LuciDoor and MarsSnake backdoors.</description><pubDate>Tue, 24 Feb 2026 12:21:43 GMT</pubDate><category>UnsolicitedBooker</category><category>LuciDoor</category><category>MarsSnake</category><category>Telecommunications</category><category>Kyrgyzstan</category><category>Tajikistan</category><category>Espionage</category></item><item><title>APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe</title><link>https://runtimerebel.com/blog/apt28-operation-macromaze-webhook-driven-macro-execution-targeting-western-europe</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-operation-macromaze-webhook-driven-macro-execution-targeting-western-europe</guid><description>Analysis of a targeted campaign attributed to APT28, utilizing macro-enabled documents and legitimate webhook services for command-and-control obfuscation.</description><pubDate>Tue, 24 Feb 2026 04:40:50 GMT</pubDate><category>APT28</category><category>MacroMaze</category><category>Webhooks</category><category>Russia</category><category>Espionage</category></item><item><title>Iranian APT MuddyWater Orchestrates Operation Olalampo Targeting MENA Infrastructure</title><link>https://runtimerebel.com/blog/iranian-apt-muddywater-orchestrates-operation-olalampo-targeting-mena-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-apt-muddywater-orchestrates-operation-olalampo-targeting-mena-infrastructure</guid><description>Analysis of a new Iranian cyber-espionage campaign utilizing GhostFetch, CHAR, and HTTP_VIP malware families against organizations in the Middle East and North Africa.</description><pubDate>Mon, 23 Feb 2026 08:19:55 GMT</pubDate><category>MuddyWater</category><category>APT</category><category>Espionage</category><category>MENA</category><category>GhostFetch</category></item></channel></rss>