<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Living-off-the-Land</title><description>Cybersecurity articles tagged #Living-off-the-Land on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Node.js Abuse: Attackers Deploy Malware via Trusted Runtime</title><link>https://runtimerebel.com/blog/node-js-abuse-attackers-deploy-malware-via-trusted-runtime</link><guid isPermaLink="true">https://runtimerebel.com/blog/node-js-abuse-attackers-deploy-malware-via-trusted-runtime</guid><description>Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.</description><pubDate>Thu, 03 Sep 2026 12:22:47 GMT</pubDate><category>Node Js</category><category>Malware Delivery</category><category>ClickFix</category><category>Living-off-the-Land</category><category>EtherHiding</category></item><item><title>Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics</title><link>https://runtimerebel.com/blog/microsoft-removes-wmic-tool-in-windows-11-to-curb-living-off-the-land-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-removes-wmic-tool-in-windows-11-to-curb-living-off-the-land-tactics</guid><description>Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.</description><pubDate>Tue, 18 Aug 2026 08:25:06 GMT</pubDate><category>Microsoft</category><category>Windows 11</category><category>Ransomware</category><category>Malware</category><category>Living-off-the-Land</category></item><item><title>Finance Executive Email Compromise via Native Windows Tools</title><link>https://runtimerebel.com/blog/finance-executive-email-compromise-via-native-windows-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/finance-executive-email-compromise-via-native-windows-tools</guid><description>A monthslong campaign targeted a global stock exchange executive, leveraging native Windows tools for persistence and unauthorized email monitoring.</description><pubDate>Wed, 03 Jun 2026 13:50:15 GMT</pubDate><category>Financial Sector</category><category>Email Security</category><category>Living-off-the-Land</category><category>M365 Security</category></item><item><title>Microsoft Coreutils for Windows: Security and Memory Safety Analysis</title><link>https://runtimerebel.com/blog/microsoft-coreutils-for-windows-security-and-memory-safety-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-coreutils-for-windows-security-and-memory-safety-analysis</guid><description>Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.</description><pubDate>Wed, 03 Jun 2026 01:09:39 GMT</pubDate><category>Microsoft</category><category>Coreutils</category><category>Rust</category><category>Windows Security</category><category>Living-off-the-Land</category></item><item><title>Weaponized Trust: Analyzing the Abuse of Administrative Utilities</title><link>https://runtimerebel.com/blog/weaponized-trust-analyzing-the-abuse-of-administrative-utilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/weaponized-trust-analyzing-the-abuse-of-administrative-utilities</guid><description>Research reveals how threat actors leverage legitimate tools like PowerShell and WMIC to bypass detection by masquerading as routine administration.</description><pubDate>Fri, 15 May 2026 12:44:24 GMT</pubDate><category>Living-off-the-Land</category><category>PowerShell</category><category>Wmic</category><category>Adversary Tactics</category><category>Bitdefender</category></item><item><title>GopherWhisper APT Abuses Legitimate Services in Government Attacks</title><link>https://runtimerebel.com/blog/gopherwhisper-apt-abuses-legitimate-services-in-government-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/gopherwhisper-apt-abuses-legitimate-services-in-government-attacks</guid><description>China-linked APT GopherWhisper targets Southeast Asian governments using Go-based backdoors and legitimate cloud services for stealthy C2 communications.</description><pubDate>Sat, 25 Apr 2026 12:20:45 GMT</pubDate><category>GopherWhisper</category><category>Go Based Malware</category><category>Southeast Asia</category><category>Government Targeting</category><category>Living-off-the-Land</category></item><item><title>Microsoft Defender Binaries Exploited as Attack Tools</title><link>https://runtimerebel.com/blog/microsoft-defender-binaries-exploited-as-attack-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-binaries-exploited-as-attack-tools</guid><description>Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.</description><pubDate>Wed, 22 Apr 2026 08:44:37 GMT</pubDate><category>Microsoft Defender</category><category>Living-off-the-Land</category><category>MpCmdRun Exe</category><category>LockBit</category><category>EDR Bypass</category></item><item><title>Mitigating the Rise of Trusted Tool Abuse in Modern Cyberattacks</title><link>https://runtimerebel.com/blog/mitigating-the-rise-of-trusted-tool-abuse-in-modern-cyberattacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-the-rise-of-trusted-tool-abuse-in-modern-cyberattacks</guid><description>Explore why threat actors are pivoting from malware to Living-off-the-Land (LotL) techniques by abusing trusted administrative tools and native binaries.</description><pubDate>Wed, 01 Apr 2026 12:26:47 GMT</pubDate><category>Living-off-the-Land</category><category>LOTL</category><category>Adversary Ttps</category><category>Endpoint Security</category><category>Defense Evasion</category></item></channel></rss>