<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Iran</title><description>Cybersecurity articles tagged #Iran on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>U.S. Sanctions Iran-Linked Hackers Targeting Critical Infrastructure</title><link>https://runtimerebel.com/blog/u-s-sanctions-iran-linked-hackers-targeting-critical-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/u-s-sanctions-iran-linked-hackers-targeting-critical-infrastructure</guid><description>U.S. Treasury sanctions Iran-linked cyber actors, including Mabna Institute members, for critical infrastructure breaches and cyber theft.</description><pubDate>Wed, 26 Aug 2026 00:41:56 GMT</pubDate><category>Iran</category><category>Sanctions</category><category>Critical Infrastructure</category><category>MOIS</category><category>Cyber Espionage</category></item><item><title>US Charges Iranian Hackers in $3.4B Intellectual Property Theft</title><link>https://runtimerebel.com/blog/us-charges-iranian-hackers-in-3-4b-intellectual-property-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-charges-iranian-hackers-in-3-4b-intellectual-property-theft</guid><description>US charges 17 Iranian hackers from Mabna Institute for a state-sponsored campaign stealing 31.5 TB of academic and corporate intellectual property since 2013.</description><pubDate>Wed, 19 Aug 2026 16:22:00 GMT</pubDate><category>Iran</category><category>Cyber Espionage</category><category>DOJ</category><category>Mabna Institute</category><category>Intellectual Property Theft</category></item><item><title>Multistate Water System Attacks Target Exposed PLCs</title><link>https://runtimerebel.com/blog/multistate-water-system-attacks-target-exposed-plcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/multistate-water-system-attacks-target-exposed-plcs</guid><description>Attacks targeting poorly secured, internet-exposed PLCs in water systems are widening across multiple U.S. states, with Iran suspected.</description><pubDate>Tue, 11 Aug 2026 08:46:26 GMT</pubDate><category>ICS</category><category>OT Security</category><category>Critical Infrastructure</category><category>Iran</category><category>Water Utilities</category></item><item><title>Iran-Backed Cyberattacks Target Minnesota Water Utilities</title><link>https://runtimerebel.com/blog/iran-backed-cyberattacks-target-minnesota-water-utilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-backed-cyberattacks-target-minnesota-water-utilities</guid><description>Iran-backed threat actors targeted over 30 Minnesota water utilities, highlighting critical infrastructure vulnerabilities. Learn about TTPs and mitigation strategies.</description><pubDate>Fri, 31 Jul 2026 02:56:58 GMT</pubDate><category>Iran</category><category>Water Utilities</category><category>Critical Infrastructure</category><category>ICS OT Security</category><category>Minnesota</category><category>Nation State</category></item><item><title>Diverse Threat Landscape: Military Tracking, macOS Malware, Defense Ransomware</title><link>https://runtimerebel.com/blog/diverse-threat-landscape-military-tracking-macos-malware-defense-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/diverse-threat-landscape-military-tracking-macos-malware-defense-ransomware</guid><description>Analysis of diverse threats including reported Iranian tracking of US military phones, CrashStealer macOS malware, ransomware on a naval firm, and a Lidl data breach.</description><pubDate>Fri, 17 Jul 2026 17:14:58 GMT</pubDate><category>Iran</category><category>US Military</category><category>CrashStealer</category><category>macOS Malware</category><category>Ransomware</category><category>Naval Defense</category><category>TKMS</category><category>Lidl</category><category>Data Breach</category></item><item><title>AI-Enhanced Cyber Operations: Analyzing Iran&apos;s Asymmetric Playbook</title><link>https://runtimerebel.com/blog/ai-enhanced-cyber-operations-analyzing-iran-s-asymmetric-playbook</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-enhanced-cyber-operations-analyzing-iran-s-asymmetric-playbook</guid><description>Analysis of how Iranian state actors integrate artificial intelligence into cyber operations, influence campaigns, and domestic surveillance for asymmetric gains.</description><pubDate>Thu, 16 Jul 2026 14:10:25 GMT</pubDate><category>Iran</category><category>Artificial Intelligence</category><category>APT</category><category>Influence Operations</category><category>Cyber Warfare</category></item><item><title>Iran Cyber Focus Expands: Securing Internet-Facing Vulnerabilities</title><link>https://runtimerebel.com/blog/iran-cyber-focus-expands-securing-internet-facing-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-cyber-focus-expands-securing-internet-facing-vulnerabilities</guid><description>Iranian state-sponsored cyber operations are broadening targets beyond critical infrastructure. All organizations must secure Internet-facing systems.</description><pubDate>Fri, 10 Jul 2026 03:33:44 GMT</pubDate><category>Iran</category><category>Nation State</category><category>Cyber Espionage</category><category>Vulnerability Management</category><category>Internet Facing Vulnerabilities</category></item><item><title>Iran-Linked Hackers Deploy New Cavern C2 Against Israeli Targets</title><link>https://runtimerebel.com/blog/iran-linked-hackers-deploy-new-cavern-c2-against-israeli-targets</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-linked-hackers-deploy-new-cavern-c2-against-israeli-targets</guid><description>Iranian state-sponsored threat actors are using a novel modular C2 framework, Cavern (Cav3rn), to compromise Israeli IT and government entities.</description><pubDate>Mon, 06 Jul 2026 21:38:48 GMT</pubDate><category>Cavern</category><category>Cav3rn</category><category>Iran</category><category>MOIS</category><category>Israeli Organizations</category><category>State Sponsored</category><category>Threat Cluster</category></item><item><title>Iranian-Nexus TAG-182 Deploys MarkiRAT Android Surveillance</title><link>https://runtimerebel.com/blog/iranian-nexus-tag-182-deploys-markirat-android-surveillance</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-nexus-tag-182-deploys-markirat-android-surveillance</guid><description>Runtime Rebel analyzes Iranian-nexus TAG-182&apos;s use of MarkiRAT malware. Disguised as fake VPN/media apps, it conducts cyber surveillance against domestic targets.</description><pubDate>Thu, 02 Jul 2026 07:41:52 GMT</pubDate><category>TAG 182</category><category>MarkiRAT</category><category>Iran</category><category>Cyber Surveillance</category><category>Android Malware</category><category>Mobile Threat</category><category>APT</category></item><item><title>Iranian &amp; Russian Cyber-Enabled Maritime Sanctions Evasion Tactics</title><link>https://runtimerebel.com/blog/iranian-russian-cyber-enabled-maritime-sanctions-evasion-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-russian-cyber-enabled-maritime-sanctions-evasion-tactics</guid><description>Explore the sophisticated cyber tactics used by Iranian and Russian shadow fleets to evade sanctions, leveraging fake maritime websites and fraudulent documents.</description><pubDate>Fri, 12 Jun 2026 09:43:20 GMT</pubDate><category>Iran</category><category>Russia</category><category>Sanctions Evasion</category><category>Maritime Security</category><category>Shadow Fleet</category><category>Fraud</category><category>Digital Identity</category><category>Illicit Shipping</category></item><item><title>OFAC Sanctions Nobitex: Disrupting Ransomware &amp; Terror Finance</title><link>https://runtimerebel.com/blog/ofac-sanctions-nobitex-disrupting-ransomware-terror-finance</link><guid isPermaLink="true">https://runtimerebel.com/blog/ofac-sanctions-nobitex-disrupting-ransomware-terror-finance</guid><description>The U.S. Treasury sanctions Nobitex, Iran&apos;s largest crypto exchange, for facilitating terrorist financing and ransomware payments.</description><pubDate>Wed, 03 Jun 2026 21:10:45 GMT</pubDate><category>Nobitex</category><category>OFAC</category><category>Sanctions</category><category>Cryptocurrency</category><category>Ransomware</category><category>Iran</category><category>Terrorist Financing</category></item><item><title>Handala Brand Evolution: Iran MOIS Shifts to Hybrid Physical Attacks</title><link>https://runtimerebel.com/blog/handala-brand-evolution-iran-mois-shifts-to-hybrid-physical-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/handala-brand-evolution-iran-mois-shifts-to-hybrid-physical-attacks</guid><description>Iran’s MOIS expands the Handala brand into hybrid operations, combining cyber espionage with physical sabotage targeting U.S. and Israeli interests.</description><pubDate>Tue, 02 Jun 2026 17:39:53 GMT</pubDate><category>Handala</category><category>MOIS</category><category>Iran</category><category>Cyber Physical</category><category>Espionage</category><category>Israel</category><category>Proxy Warfare</category></item><item><title>Iranian APT33 Targets Aviation with Updated MimicC2 and PowerLess</title><link>https://runtimerebel.com/blog/iranian-apt33-targets-aviation-with-updated-mimicc2-and-powerless</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-apt33-targets-aviation-with-updated-mimicc2-and-powerless</guid><description>Iranian APT Nimbus Manticore (APT33) targets aviation and software firms using new MimicC2 framework and updated PowerLess tools for stealthy operations.</description><pubDate>Tue, 26 May 2026 20:46:55 GMT</pubDate><category>APT33</category><category>Nimbus Manticore</category><category>Iran</category><category>Aviation</category><category>Software</category><category>MimicC2</category><category>PowerLess</category><category>Cyber Espionage</category><category>Critical Infrastructure</category></item><item><title>MuddyWater 2026 Espionage: DLL Side-Loading Across 9 Countries</title><link>https://runtimerebel.com/blog/muddywater-2026-espionage-dll-side-loading-across-9-countries</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-2026-espionage-dll-side-loading-across-9-countries</guid><description>Iranian group MuddyWater targets industrial manufacturing and financial sectors in a global 2026 espionage campaign using DLL side-loading techniques.</description><pubDate>Tue, 26 May 2026 17:14:39 GMT</pubDate><category>MuddyWater</category><category>APT33</category><category>DLL Side Loading</category><category>Espionage</category><category>Iran</category></item><item><title>Iranian Cyber Offensive Targets Critical Fuel Tank Gauge Systems</title><link>https://runtimerebel.com/blog/iranian-cyber-offensive-targets-critical-fuel-tank-gauge-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-cyber-offensive-targets-critical-fuel-tank-gauge-systems</guid><description>Iranian threat actors are targeting insecure automatic tank gauges in fuel infrastructure, posing risks of physical disruption and environmental damage.</description><pubDate>Mon, 18 May 2026 17:04:16 GMT</pubDate><category>Iran</category><category>ATG</category><category>Critical Infrastructure</category><category>OT Security</category><category>Cyber Physical</category></item><item><title>MuddyWater Targets South Korean Electronics Maker in Espionage Campaign</title><link>https://runtimerebel.com/blog/muddywater-targets-south-korean-electronics-maker-in-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-targets-south-korean-electronics-maker-in-espionage-campaign</guid><description>Iran-linked MuddyWater (Seedworm) group launched a cyber-espionage campaign against a major South Korean electronics maker and other global entities.</description><pubDate>Thu, 14 May 2026 00:55:56 GMT</pubDate><category>MuddyWater</category><category>Seedworm</category><category>Static Kitten</category><category>Iran</category><category>Cyber Espionage</category><category>South Korea</category><category>Electronics Maker</category><category>APT</category></item><item><title>US Strategic Pivot: Cyber Risk and Geopolitical Shift Analysis</title><link>https://runtimerebel.com/blog/us-strategic-pivot-cyber-risk-and-geopolitical-shift-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-strategic-pivot-cyber-risk-and-geopolitical-shift-analysis</guid><description>Analysis of the US strategic shift toward force-driven security and its implications for cyber threats from China, Russia, Iran, and criminal groups.</description><pubDate>Thu, 30 Apr 2026 16:41:48 GMT</pubDate><category>Geopolitics</category><category>China</category><category>Russia</category><category>Iran</category><category>Transnational Organized Crime</category><category>Western Hemisphere</category></item><item><title>Fast16 Malware: Analyzing the Precursor to Stuxnet Sabotage</title><link>https://runtimerebel.com/blog/fast16-malware-analyzing-the-precursor-to-stuxnet-sabotage</link><guid isPermaLink="true">https://runtimerebel.com/blog/fast16-malware-analyzing-the-precursor-to-stuxnet-sabotage</guid><description>Analysis of the Fast16 malware, a state-sponsored tool designed to sabotage high-precision mathematical simulations and physical computation processes.</description><pubDate>Thu, 30 Apr 2026 12:42:39 GMT</pubDate><category>Fast16</category><category>Stuxnet</category><category>Ics Sabotage</category><category>State Sponsored</category><category>Iran</category></item><item><title>UK Cyber Chief: Russia, Iran, China Drive Top Cyber Threats</title><link>https://runtimerebel.com/blog/uk-cyber-chief-russia-iran-china-drive-top-cyber-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-cyber-chief-russia-iran-china-drive-top-cyber-threats</guid><description>NCSC warns British businesses of escalating cyber threats from state-sponsored groups in Russia, Iran, and China, urging preparedness for potential large-scale attacks.</description><pubDate>Wed, 22 Apr 2026 20:26:36 GMT</pubDate><category>UK</category><category>NCSC</category><category>Russia</category><category>Iran</category><category>China</category><category>Nation State</category><category>Cyber Warfare</category><category>Critical Infrastructure</category></item><item><title>Iran Geopolitical Tensions: Cyber Implications &amp; Preparedness</title><link>https://runtimerebel.com/blog/iran-geopolitical-tensions-cyber-implications-preparedness</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-geopolitical-tensions-cyber-implications-preparedness</guid><description>Examine the potential cybersecurity implications of escalating geopolitical tensions involving Iran, focusing on nation-state TTPs and organizational preparedness…</description><pubDate>Tue, 14 Apr 2026 20:28:00 GMT</pubDate><category>Iran</category><category>Nation State</category><category>Geopolitical Threat</category><category>Cyber Warfare</category><category>Critical Infrastructure</category><category>APT</category><category>Threat Intelligence</category></item><item><title>Iranian Actors Target Rockwell PLCs: 4,000 US Devices Exposed</title><link>https://runtimerebel.com/blog/iranian-actors-target-rockwell-plcs-4000-us-devices-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-actors-target-rockwell-plcs-4000-us-devices-exposed</guid><description>Iranian-linked cyber actors have identified nearly 4,000 exposed US industrial control systems, primarily Rockwell Automation PLCs, raising critical infrastructure…</description><pubDate>Fri, 10 Apr 2026 16:24:02 GMT</pubDate><category>Iran</category><category>Rockwell Automation</category><category>PLC</category><category>ICS</category><category>Critical Infrastructure</category><category>Cyberattacks</category><category>Exposure</category></item><item><title>Iran-Linked Cyber Attacks Persist Despite Israel-Hezbollah Ceasefire</title><link>https://runtimerebel.com/blog/iran-linked-cyber-attacks-persist-despite-israel-hezbollah-ceasefire</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-linked-cyber-attacks-persist-despite-israel-hezbollah-ceasefire</guid><description>Iran-affiliated threat actors maintain operational tempo against US critical infrastructure, disregarding kinetic pauses in Middle East regional conflicts.</description><pubDate>Thu, 09 Apr 2026 04:52:31 GMT</pubDate><category>Iran</category><category>IRGC</category><category>Critical Infrastructure</category><category>Cyber Av3ngers</category><category>ICS</category></item><item><title>Iran-Linked Cyber Av3ngers Target US Water Sector PLCs</title><link>https://runtimerebel.com/blog/iran-linked-cyber-av3ngers-target-us-water-sector-plcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-linked-cyber-av3ngers-target-us-water-sector-plcs</guid><description>US federal agencies warn of Iran-linked Cyber Av3ngers targeting Unitronics PLCs in critical infrastructure. Learn how to detect and mitigate these OT attacks.</description><pubDate>Wed, 08 Apr 2026 04:54:42 GMT</pubDate><category>Cyber Av3ngers</category><category>PLC</category><category>Unitronics</category><category>OT Security</category><category>Iran</category></item><item><title>Quantum Geopolitics: Cyber Threats in an Era of Iran Conflict</title><link>https://runtimerebel.com/blog/quantum-geopolitics-cyber-threats-in-an-era-of-iran-conflict</link><guid isPermaLink="true">https://runtimerebel.com/blog/quantum-geopolitics-cyber-threats-in-an-era-of-iran-conflict</guid><description>Analyze how the shift toward quantum geopolitics and Iranian proxy conflicts impact global cyber stability and critical infrastructure protection.</description><pubDate>Thu, 02 Apr 2026 08:35:45 GMT</pubDate><category>Iran</category><category>Geopolitics</category><category>APT</category><category>Middle East</category><category>Critical Infrastructure</category></item><item><title>Iranian Hackers Target Kash Patel: US Offers $10M Bounty</title><link>https://runtimerebel.com/blog/iranian-hackers-target-kash-patel-us-offers-10m-bounty</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-hackers-target-kash-patel-us-offers-10m-bounty</guid><description>The FBI confirms Iranian state-sponsored hackers compromised Kash Patel’s personal email, leading the U.S. to offer a $10M reward for information.</description><pubDate>Mon, 30 Mar 2026 08:42:33 GMT</pubDate><category>Iran</category><category>FBI</category><category>Kash Patel</category><category>Election Interference</category><category>State Sponsored</category><category>APT</category></item><item><title>Iranian-Linked Handala Group Breaches Kash Patel&apos;s Personal Email</title><link>https://runtimerebel.com/blog/iranian-linked-handala-group-breaches-kash-patel-s-personal-email</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-linked-handala-group-breaches-kash-patel-s-personal-email</guid><description>FBI confirms Iranian-linked Handala hackers breached Director nominee Kash Patel&apos;s personal email, leaking documents and highlighting spear-phishing risks.</description><pubDate>Mon, 30 Mar 2026 00:41:00 GMT</pubDate><category>Handala</category><category>Iran</category><category>Kash Patel</category><category>FBI</category><category>Spear Phishing</category><category>Espionage</category></item><item><title>Weaponized Surveillance: How Israel Hijacked Iran&apos;s Camera Network</title><link>https://runtimerebel.com/blog/weaponized-surveillance-how-israel-hijacked-iran-s-camera-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/weaponized-surveillance-how-israel-hijacked-iran-s-camera-network</guid><description>Analysis of the compromise of Iran&apos;s surveillance infrastructure by Israel to facilitate kinetic targeting and high-value intelligence operations.</description><pubDate>Tue, 24 Mar 2026 12:24:55 GMT</pubDate><category>Iran</category><category>Israel</category><category>CCTV Security</category><category>Nation State</category><category>Surveillance Weaponization</category></item><item><title>TeamPCP Targets Kubernetes Clusters with Iran-Specific Wiper Malware</title><link>https://runtimerebel.com/blog/teampcp-targets-kubernetes-clusters-with-iran-specific-wiper-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-targets-kubernetes-clusters-with-iran-specific-wiper-malware</guid><description>TeamPCP is targeting misconfigured Kubernetes clusters to deploy a data-wiping script that specifically triggers on Iranian system configurations and locales.</description><pubDate>Mon, 23 Mar 2026 20:17:25 GMT</pubDate><category>TeamPCP</category><category>Kubernetes</category><category>Wiper Malware</category><category>Cloud Security</category><category>Iran</category></item><item><title>CanisterWorm Wiper Attacks Target Iran via Cloud Misconfigurations</title><link>https://runtimerebel.com/blog/canisterworm-wiper-attacks-target-iran-via-cloud-misconfigurations</link><guid isPermaLink="true">https://runtimerebel.com/blog/canisterworm-wiper-attacks-target-iran-via-cloud-misconfigurations</guid><description>Analysis of the CanisterWorm wiper targeting Iranian systems through cloud service vulnerabilities, shifting from financial extortion to destructive operations.</description><pubDate>Mon, 23 Mar 2026 16:26:55 GMT</pubDate><category>CanisterWorm</category><category>Iran</category><category>Wiper</category><category>Cloud Security</category><category>Data Destruction</category></item><item><title>Iranian Handala Group Leverages Telegram for Malware Delivery and C2</title><link>https://runtimerebel.com/blog/iranian-handala-group-leverages-telegram-for-malware-delivery-and-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-handala-group-leverages-telegram-for-malware-delivery-and-c2</guid><description>FBI alerts organizations to Handala, an Iranian MOIS-linked group using Telegram APIs for data exfiltration, ransomware, and wiper attacks across sectors.</description><pubDate>Mon, 23 Mar 2026 12:23:29 GMT</pubDate><category>Handala</category><category>Iran</category><category>Telegram</category><category>MOIS</category><category>Ransomware</category><category>Wiper Malware</category><category>FBI Warning</category></item><item><title>Iranian Cyber Infrastructure Hardening Ahead of Operation Epic Fury</title><link>https://runtimerebel.com/blog/iranian-cyber-infrastructure-hardening-ahead-of-operation-epic-fury</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-cyber-infrastructure-hardening-ahead-of-operation-epic-fury</guid><description>Analysis of Iran&apos;s six-month buildup of US-based shell companies and resilient cyber infrastructure to survive kinetic strikes and maintain hacking operations.</description><pubDate>Thu, 19 Mar 2026 16:25:33 GMT</pubDate><category>Iran</category><category>Emennet Pasargad</category><category>Epic Fury</category><category>Infrastructure Hardening</category><category>State Sponsored</category></item><item><title>EU Sanctions China and Iran Entities Over APT31 Cyber Operations</title><link>https://runtimerebel.com/blog/eu-sanctions-china-and-iran-entities-over-apt31-cyber-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/eu-sanctions-china-and-iran-entities-over-apt31-cyber-operations</guid><description>The European Union imposes sanctions on Chinese and Iranian entities linked to APT31 and state-sponsored cyber espionage targeting democratic institutions.</description><pubDate>Thu, 19 Mar 2026 08:18:51 GMT</pubDate><category>APT31</category><category>Wuhan Xiaoruizhi</category><category>Sanctions</category><category>China</category><category>Iran</category><category>Cyber Diplomacy</category></item><item><title>Poland’s Nuclear Center Targeted in Suspected Iranian Cyberattack</title><link>https://runtimerebel.com/blog/polands-nuclear-center-targeted-in-suspected-iranian-cyberattack</link><guid isPermaLink="true">https://runtimerebel.com/blog/polands-nuclear-center-targeted-in-suspected-iranian-cyberattack</guid><description>Polish officials investigate a cyberattack at the NCBJ nuclear center. Initial evidence points to Iran, but investigators warn of potential false flag tactics.</description><pubDate>Mon, 16 Mar 2026 12:25:26 GMT</pubDate><category>NCBJ</category><category>Poland</category><category>Critical Infrastructure</category><category>Iran</category><category>APT</category></item><item><title>Iranian MOIS Collusion with Cybercriminals: Evolving Hybrid Threat</title><link>https://runtimerebel.com/blog/iranian-mois-collusion-with-cybercriminals-evolving-hybrid-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-mois-collusion-with-cybercriminals-evolving-hybrid-threat</guid><description>Iranian state-sponsored APTs, linked to MOIS, are now directly collaborating with cybercriminal organizations, escalating hybrid cyber operations. Defenders must adapt.</description><pubDate>Fri, 13 Mar 2026 00:35:19 GMT</pubDate><category>Iran</category><category>MOIS</category><category>Nation State</category><category>Cybercrime</category><category>APT</category><category>Hybrid Warfare</category><category>Threat Intelligence</category></item><item><title>Chinese Nexus Actors Pivot to Qatar: Geopolitical Espionage</title><link>https://runtimerebel.com/blog/chinese-nexus-actors-pivot-to-qatar-geopolitical-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-nexus-actors-pivot-to-qatar-geopolitical-espionage</guid><description>Analysis of Chinese Nexus actors&apos; shift to targeting Qatari entities amid Iranian conflict. Understand their adaptable TTPs and fortify defenses.</description><pubDate>Wed, 11 Mar 2026 16:31:22 GMT</pubDate><category>Chinese Nexus Actors</category><category>Qatar</category><category>Iran</category><category>Geopolitics</category><category>Espionage</category><category>Nation State APT</category></item><item><title>Stryker Wiper Attack: Iran-Backed Group Targets Medtech Operations</title><link>https://runtimerebel.com/blog/stryker-wiper-attack-iran-backed-group-targets-medtech-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/stryker-wiper-attack-iran-backed-group-targets-medtech-operations</guid><description>Analysis of a destructive wiper attack claimed by an Iran-backed hacktivist group against medical technology firm Stryker, disrupting global operations.</description><pubDate>Wed, 11 Mar 2026 16:30:57 GMT</pubDate><category>Iran</category><category>Wiper Malware</category><category>Stryker</category><category>Medtech</category><category>Critical Infrastructure</category><category>Destructive Attack</category><category>Hacktivism</category></item><item><title>Iran Integrates Cyber-Kinetic Operations into Military Doctrine</title><link>https://runtimerebel.com/blog/iran-integrates-cyber-kinetic-operations-into-military-doctrine</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-integrates-cyber-kinetic-operations-into-military-doctrine</guid><description>Iran is leveraging cyber operations, including IP camera exploitation, to support kinetic military strikes and physical asset targeting globally.</description><pubDate>Fri, 06 Mar 2026 16:23:44 GMT</pubDate><category>Iran</category><category>Cyber Kinetic</category><category>Iot Security</category><category>Physical Security</category><category>Threat Intelligence</category></item><item><title>Nation-State Cyber Operation: Israel&apos;s Compromise of Iranian Traffic Cameras</title><link>https://runtimerebel.com/blog/nation-state-cyber-operation-israel-s-compromise-of-iranian-traffic-cameras</link><guid isPermaLink="true">https://runtimerebel.com/blog/nation-state-cyber-operation-israel-s-compromise-of-iranian-traffic-cameras</guid><description>Analysis of the reported Israeli cyber operation targeting Iranian traffic cameras, detailing implications for critical infrastructure security and cyber-physical…</description><pubDate>Thu, 05 Mar 2026 20:17:25 GMT</pubDate><category>Israel</category><category>Iran</category><category>Traffic Cameras</category><category>Cyber Espionage</category><category>Nation State Attack</category><category>Critical Infrastructure</category><category>OT Security</category></item><item><title>Iran-US/Israel Cyber Conflict: Geopolitical &amp; Cyber Threat Analysis</title><link>https://runtimerebel.com/blog/iran-us-israel-cyber-conflict-geopolitical-cyber-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-us-israel-cyber-conflict-geopolitical-cyber-threat-analysis</guid><description>Analysis of the ongoing US-Israeli strikes on Iran, covering cyber, physical, and geopolitical dimensions.</description><pubDate>Thu, 05 Mar 2026 00:36:15 GMT</pubDate><category>Iran</category><category>US</category><category>Israel</category><category>Geopolitical Conflict</category><category>Nation State</category><category>Cyber Warfare</category></item><item><title>Geopolitical Strikes on AWS Data Centers: Mitigating Physical Disaster Risk</title><link>https://runtimerebel.com/blog/geopolitical-strikes-on-aws-data-centers-mitigating-physical-disaster-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-strikes-on-aws-data-centers-mitigating-physical-disaster-risk</guid><description>Iranian drone strikes damaged AWS data centers in UAE and Bahrain, highlighting critical vulnerabilities to physical disasters and the urgent need for geo-redundancy.</description><pubDate>Tue, 03 Mar 2026 20:12:52 GMT</pubDate><category>AWS</category><category>Data Center</category><category>Physical Attack</category><category>Iran</category><category>Cloud Security</category><category>Disaster Recovery</category><category>Geopolitical Threat</category></item><item><title>Geopolitical Cyber Threat: Iran Conflict Implications for Defenders</title><link>https://runtimerebel.com/blog/geopolitical-cyber-threat-iran-conflict-implications-for-defenders</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-cyber-threat-iran-conflict-implications-for-defenders</guid><description>An analysis of the ongoing cyber, physical, and geopolitical components of the US-Israeli strikes on Iran and its implications for cybersecurity professionals.</description><pubDate>Tue, 03 Mar 2026 00:37:34 GMT</pubDate><category>Iran</category><category>Geopolitics</category><category>Nation State</category><category>Cyber Conflict</category><category>Threat Intelligence</category></item><item><title>Iranian Cyberattack Risks Escalate Amid Middle-East Conflict</title><link>https://runtimerebel.com/blog/iranian-cyberattack-risks-escalate-amid-middle-east-conflict</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-cyberattack-risks-escalate-amid-middle-east-conflict</guid><description>The NCSC warns UK organizations of increased Iranian state-sponsored cyber threats targeting critical infrastructure and utilizing advanced phishing tactics.</description><pubDate>Mon, 02 Mar 2026 16:18:24 GMT</pubDate><category>NCSC</category><category>Iran</category><category>APT33</category><category>APT35</category><category>Middle East</category></item><item><title>Analysis of Iran&apos;s 2026 Total Internet Shutdown and NIN Architecture</title><link>https://runtimerebel.com/blog/analysis-of-iran-s-2026-total-internet-shutdown-and-nin-architecture</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-iran-s-2026-total-internet-shutdown-and-nin-architecture</guid><description>Technical review of Iran&apos;s National Information Network and the shift toward total communications blackouts as a tool for state-level control.</description><pubDate>Fri, 27 Feb 2026 12:18:23 GMT</pubDate><category>Iran</category><category>NIN</category><category>Internet Shutdown</category><category>Geopolitics</category><category>Censorship</category></item><item><title>MuddyWater Deploys BugSleep Backdoor in Targeted Regional Campaigns</title><link>https://runtimerebel.com/blog/muddywater-deploys-bugsleep-backdoor-in-targeted-regional-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-deploys-bugsleep-backdoor-in-targeted-regional-campaigns</guid><description>Iranian state actor MuddyWater introduces the custom BugSleep backdoor, targeting Middle Eastern and African entities using spear-phishing and RMM abuse.</description><pubDate>Tue, 24 Feb 2026 08:22:38 GMT</pubDate><category>MuddyWater</category><category>BugSleep</category><category>MOIS</category><category>Spear Phishing</category><category>RMM Abuse</category><category>Iran</category><category>Cyber Espionage</category></item></channel></rss>