<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Information Stealer</title><description>Cybersecurity articles tagged #Information Stealer on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>REVSTEALER Modules Disable Defenses, Deploy Miner, Steal Data</title><link>https://runtimerebel.com/blog/revstealer-modules-disable-defenses-deploy-miner-steal-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/revstealer-modules-disable-defenses-deploy-miner-steal-data</guid><description>Elastic Security unveils four REVSTEALER-linked modules that disable Windows defenses, deploy crypto miners, and exfiltrate sensitive user data.</description><pubDate>Sun, 06 Sep 2026 17:53:44 GMT</pubDate><category>Information Stealer</category><category>Cryptomining</category><category>Windows Update</category><category>REVSTEALER</category><category>Windows Defender</category></item><item><title>Solidity Pro VS Code Extensions Steal Crypto Wallets &amp; Credentials</title><link>https://runtimerebel.com/blog/solidity-pro-vs-code-extensions-steal-crypto-wallets-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/solidity-pro-vs-code-extensions-steal-crypto-wallets-credentials</guid><description>Malicious &apos;Solidity Pro&apos; VS Code extensions steal crypto wallets, API keys, and credentials, using delayed activation to evade detection. Immediate removal is advised.</description><pubDate>Mon, 10 Aug 2026 09:08:16 GMT</pubDate><category>VS Code</category><category>Information Stealer</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>Solidity Pro</category></item><item><title>Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware</title><link>https://runtimerebel.com/blog/bing-ads-promote-fake-claude-app-deliver-sectoprat-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/bing-ads-promote-fake-claude-app-deliver-sectoprat-malware</guid><description>A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.</description><pubDate>Thu, 23 Jul 2026 21:06:56 GMT</pubDate><category>Sectop RAT</category><category>Malvertising</category><category>Bing Ads</category><category>Claude AI</category><category>Information Stealer</category><category>Phishing</category></item><item><title>ClickLock macOS Malware: Password Theft via Forced Login Prompt</title><link>https://runtimerebel.com/blog/clicklock-macos-malware-password-theft-via-forced-login-prompt</link><guid isPermaLink="true">https://runtimerebel.com/blog/clicklock-macos-malware-password-theft-via-forced-login-prompt</guid><description>ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password.</description><pubDate>Fri, 17 Jul 2026 02:45:47 GMT</pubDate><category>macOS</category><category>ClickLock</category><category>Information Stealer</category><category>Password Theft</category><category>Social Engineering</category></item><item><title>CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization</title><link>https://runtimerebel.com/blog/crashstealer-new-macos-info-stealer-bypasses-gatekeeper-via-notarization</link><guid isPermaLink="true">https://runtimerebel.com/blog/crashstealer-new-macos-info-stealer-bypasses-gatekeeper-via-notarization</guid><description>CrashStealer macOS malware leverages C++ and notarized droppers to evade security checks and exfiltrate validated credentials from compromised Apple devices.</description><pubDate>Mon, 13 Jul 2026 20:57:57 GMT</pubDate><category>CrashStealer</category><category>macOS Security</category><category>Information Stealer</category><category>Gatekeeper Bypass</category><category>Jamf Threat Labs</category></item><item><title>Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot &amp; PowerShell</title><link>https://runtimerebel.com/blog/veil-drop-attacks-deploy-purelog-info-stealer-via-blogspot-powershell</link><guid isPermaLink="true">https://runtimerebel.com/blog/veil-drop-attacks-deploy-purelog-info-stealer-via-blogspot-powershell</guid><description>Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.</description><pubDate>Mon, 06 Jul 2026 21:40:18 GMT</pubDate><category>Veil Drop</category><category>PureLog</category><category>Information Stealer</category><category>Blogspot</category><category>PowerShell</category><category>Fileless Malware</category><category>Securonix</category></item><item><title>OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware</title><link>https://runtimerebel.com/blog/oxloader-analysis-malicious-google-ads-deliver-castlestealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/oxloader-analysis-malicious-google-ads-deliver-castlestealer-malware</guid><description>Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.</description><pubDate>Mon, 22 Jun 2026 14:00:29 GMT</pubDate><category>OXLOADER</category><category>CastleStealer</category><category>Malvertising</category><category>Google Ads</category><category>Information Stealer</category></item><item><title>Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis</title><link>https://runtimerebel.com/blog/miasma-compromises-73-microsoft-github-repos-incident-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/miasma-compromises-73-microsoft-github-repos-incident-analysis</guid><description>Microsoft restores some GitHub repositories after 73 projects were hit by Miasma&apos;s supply chain attack to inject information stealers. Learn detection steps.</description><pubDate>Tue, 09 Jun 2026 17:00:07 GMT</pubDate><category>GitHub</category><category>Miasma</category><category>Microsoft</category><category>Supply Chain Attack</category><category>Information Stealer</category><category>Open Source Security</category></item><item><title>UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware</title><link>https://runtimerebel.com/blog/uac-0247-targets-ukrainian-healthcare-via-data-theft-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uac-0247-targets-ukrainian-healthcare-via-data-theft-malware</guid><description>UAC-0247 is targeting Ukrainian clinics and government entities using malware designed to steal data from WhatsApp and Chromium-based browsers.</description><pubDate>Thu, 16 Apr 2026 08:40:22 GMT</pubDate><category>UAC 0247</category><category>Ukraine</category><category>Healthcare Security</category><category>Information Stealer</category><category>Data Theft</category></item><item><title>CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware</title><link>https://runtimerebel.com/blog/crystalrat-malware-a-new-maas-threat-with-rat-stealer-and-prankware</link><guid isPermaLink="true">https://runtimerebel.com/blog/crystalrat-malware-a-new-maas-threat-with-rat-stealer-and-prankware</guid><description>CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a…</description><pubDate>Thu, 02 Apr 2026 00:37:19 GMT</pubDate><category>CrystalRAT</category><category>Malware as a Service</category><category>RAT</category><category>Information Stealer</category><category>Keylogger</category><category>Prankware</category><category>Telegram</category></item><item><title>GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery</title><link>https://runtimerebel.com/blog/glassworm-malware-uses-solana-dead-drops-for-stealthy-c2-delivery</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-uses-solana-dead-drops-for-stealthy-c2-delivery</guid><description>GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.</description><pubDate>Wed, 25 Mar 2026 16:31:31 GMT</pubDate><category>GlassWorm</category><category>Solana</category><category>RAT</category><category>Information Stealer</category><category>Blockchain Dead Drops</category></item></channel></rss>