<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Government</title><description>Cybersecurity articles tagged #Government on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>BusySnake Infostealer Targets Critical Infrastructure: Armored Likho&apos;s TTPs</title><link>https://runtimerebel.com/blog/busysnake-infostealer-targets-critical-infrastructure-armored-likho-s-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/busysnake-infostealer-targets-critical-infrastructure-armored-likho-s-ttps</guid><description>BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.</description><pubDate>Tue, 07 Jul 2026 03:34:06 GMT</pubDate><category>BusySnake</category><category>Infostealer</category><category>Armored Likho</category><category>Critical Infrastructure</category><category>Government</category><category>Electrical Power</category><category>Russia</category><category>Brazil</category><category>Kazakhstan</category></item><item><title>Turla&apos;s STOCKSTAY Backdoor: Analysis of Campaigns &amp; WinRAR Exploit</title><link>https://runtimerebel.com/blog/turla-s-stockstay-backdoor-analysis-of-campaigns-winrar-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/turla-s-stockstay-backdoor-analysis-of-campaigns-winrar-exploit</guid><description>Google Threat Intelligence details STOCKSTAY, Turla&apos;s .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP &amp; CVE-2025-8088.</description><pubDate>Fri, 26 Jun 2026 09:21:08 GMT</pubDate><category>Turla</category><category>STOCKSTAY</category><category>KAZUAR</category><category>APT</category><category>Cyber Espionage</category><category>Ukraine</category><category>Government</category><category>Military</category><category>CVE-2025-8088</category><category>WinRAR</category><category>NET Malware</category><category>FSB</category></item><item><title>Ghostwriter Targets Ukraine Government with Prometheus Phishing</title><link>https://runtimerebel.com/blog/ghostwriter-targets-ukraine-government-with-prometheus-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghostwriter-targets-ukraine-government-with-prometheus-phishing</guid><description>Belarus-aligned Ghostwriter (UAC-0057) targets Ukrainian government entities with Prometheus-themed phishing emails to deploy sophisticated malware. Learn detection and…</description><pubDate>Fri, 22 May 2026 20:37:28 GMT</pubDate><category>Ghostwriter</category><category>UAC 0057</category><category>UNC1151</category><category>Ukraine</category><category>Government</category><category>Phishing</category><category>Prometheus</category><category>CERT UA</category><category>APT</category></item><item><title>FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing</title><link>https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</guid><description>Belarussian APT &apos;FrostyNeighbor&apos; is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…</description><pubDate>Thu, 14 May 2026 20:38:13 GMT</pubDate><category>FrostyNeighbor</category><category>APT</category><category>Belarus</category><category>Poland</category><category>Ukraine</category><category>Espionage</category><category>Spear Phishing</category><category>Government</category><category>Nation State</category></item><item><title>AgingFly Malware: Credential Theft Operations Against Ukraine</title><link>https://runtimerebel.com/blog/agingfly-malware-credential-theft-operations-against-ukraine</link><guid isPermaLink="true">https://runtimerebel.com/blog/agingfly-malware-credential-theft-operations-against-ukraine</guid><description>Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…</description><pubDate>Thu, 16 Apr 2026 00:47:01 GMT</pubDate><category>AgingFly</category><category>Malware</category><category>Ukraine</category><category>Credential Theft</category><category>Chromium</category><category>WhatsApp</category><category>Government</category><category>Hospitals</category></item><item><title>Iranian APT Exploits Rockwell Automation PLCs: Securing Critical Infrastructure OT Devices</title><link>https://runtimerebel.com/blog/iranian-apt-exploits-rockwell-automation-plcs-securing-critical-infrastructure-ot-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-apt-exploits-rockwell-automation-plcs-securing-critical-infrastructure-ot-devices</guid><description>Iranian-affiliated APT actors are exploiting internet-facing Rockwell Automation PLCs, disrupting US critical infrastructure. Learn how to secure your OT devices and…</description><pubDate>Tue, 07 Apr 2026 20:21:14 GMT</pubDate><category>Iranian APT</category><category>Cyber Av3ngers</category><category>Rockwell Automation</category><category>Allen Bradley</category><category>PLC</category><category>OT Security</category><category>Critical Infrastructure</category><category>HMI</category><category>SCADA</category><category>Government</category><category>Water and Wastewater</category><category>Energy</category></item><item><title>CVE-2026-3502: TrueConf Zero-Day Exploited in Asia Gov Attacks</title><link>https://runtimerebel.com/blog/cve-2026-3502-trueconf-zero-day-exploited-in-asia-gov-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3502-trueconf-zero-day-exploited-in-asia-gov-attacks</guid><description>TrueConf video conferencing zero-day [CVE-2026-3502] exploited to distribute tampered updates to Southeast Asian government networks in &apos;TrueChaos&apos; campaign.</description><pubDate>Tue, 31 Mar 2026 20:18:22 GMT</pubDate><category>CVE-2026-3502</category><category>TrueConf</category><category>Zero-Day</category><category>TrueChaos</category><category>Supply Chain Attack</category><category>Government</category><category>Southeast Asia</category></item><item><title>FBI Arrests Suspect in $46M US Marshals Crypto Theft</title><link>https://runtimerebel.com/blog/fbi-arrests-suspect-in-46m-us-marshals-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-arrests-suspect-in-46m-us-marshals-crypto-theft</guid><description>A suspect linked to the theft of $46 million in cryptocurrency from the U.S. Marshals Service has been arrested. Runtime Rebel analyzes the incident and key takeaways…</description><pubDate>Thu, 05 Mar 2026 20:16:44 GMT</pubDate><category>Cryptocurrency</category><category>Theft</category><category>US Marshals Service</category><category>Government</category><category>Cybercrime</category><category>FBI</category></item><item><title>Chinese Cyberspies Exploit SaaS APIs in Global Espionage Campaign</title><link>https://runtimerebel.com/blog/chinese-cyberspies-exploit-saas-apis-in-global-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-cyberspies-exploit-saas-apis-in-global-espionage-campaign</guid><description>A suspected Chinese threat actor breached dozens of telecom firms and government agencies, using SaaS API calls to evade detection in a global espionage campaign.</description><pubDate>Wed, 25 Feb 2026 20:16:16 GMT</pubDate><category>Chinese Threat Actor</category><category>Espionage</category><category>SaaS API Abuse</category><category>Telecom</category><category>Government</category><category>Mandiant</category><category>Google GTIG</category></item><item><title>GRIDTIDE Espionage: PRC-Nexus UNC2814 Targets Telecoms Globally</title><link>https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</link><guid isPermaLink="true">https://runtimerebel.com/blog/gridtide-espionage-prc-nexus-unc2814-targets-telecoms-globally</guid><description>Google disrupts GRIDTIDE, a novel backdoor used by PRC-nexus UNC2814 for global cyber espionage against telecommunications and government entities.</description><pubDate>Wed, 25 Feb 2026 16:34:59 GMT</pubDate><category>UNC2814</category><category>GRIDTIDE</category><category>PRC Nexus</category><category>Cyber Espionage</category><category>Telecommunications</category><category>Government</category><category>Google Sheets API</category><category>SoftEther VPN</category><category>C2</category><category>Linux Malware</category><category>TTPs</category></item></channel></rss>