<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Malvertising</title><description>Cybersecurity articles tagged #Malvertising on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Vidar Stealer &amp; XMRig Campaign Leverages Malvertising, AMSI Bypass</title><link>https://runtimerebel.com/blog/vidar-stealer-xmrig-campaign-leverages-malvertising-amsi-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/vidar-stealer-xmrig-campaign-leverages-malvertising-amsi-bypass</guid><description>Financially motivated campaign delivers Vidar stealer and XMRig miner via malvertising for cracked software, targeting consumers and SMBs globally.</description><pubDate>Sun, 09 Aug 2026 01:01:35 GMT</pubDate><category>Vidar Stealer</category><category>XMRig</category><category>Malvertising</category><category>Credential Theft</category><category>Factory V3</category></item><item><title>DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft</title><link>https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</guid><description>North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.</description><pubDate>Thu, 30 Jul 2026 21:11:51 GMT</pubDate><category>macOS</category><category>Lazarus Group</category><category>Malvertising</category><category>Cryptocurrency</category><category>DPRK</category></item><item><title>SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly</title><link>https://runtimerebel.com/blog/sourtrade-malvertising-evasion-via-browser-side-bun-runtime-assembly</link><guid isPermaLink="true">https://runtimerebel.com/blog/sourtrade-malvertising-evasion-via-browser-side-bun-runtime-assembly</guid><description>The SourTrade malvertising operation bypasses security controls by using the victim&apos;s browser to assemble malicious Bun runtime executables in real-time.</description><pubDate>Sat, 25 Jul 2026 20:54:14 GMT</pubDate><category>SourTrade</category><category>Malvertising</category><category>Bun Runtime</category><category>Cryptocurrency Trading</category><category>Evasion Techniques</category></item><item><title>Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware</title><link>https://runtimerebel.com/blog/bing-ads-promote-fake-claude-app-deliver-sectoprat-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/bing-ads-promote-fake-claude-app-deliver-sectoprat-malware</guid><description>A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.</description><pubDate>Thu, 23 Jul 2026 21:06:56 GMT</pubDate><category>Sectop RAT</category><category>Malvertising</category><category>Bing Ads</category><category>Claude AI</category><category>Information Stealer</category><category>Phishing</category></item><item><title>Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software</title><link>https://runtimerebel.com/blog/vidar-infostealer-malvertising-campaign-smbs-targeted-by-fake-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/vidar-infostealer-malvertising-campaign-smbs-targeted-by-fake-software</guid><description>A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…</description><pubDate>Wed, 08 Jul 2026 17:40:40 GMT</pubDate><category>Vidar Infostealer</category><category>Malvertising</category><category>SMBs</category><category>Cryptomining</category><category>Data Theft</category><category>Pirated Software</category></item><item><title>OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware</title><link>https://runtimerebel.com/blog/oxloader-analysis-malicious-google-ads-deliver-castlestealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/oxloader-analysis-malicious-google-ads-deliver-castlestealer-malware</guid><description>Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.</description><pubDate>Mon, 22 Jun 2026 14:00:29 GMT</pubDate><category>OXLOADER</category><category>CastleStealer</category><category>Malvertising</category><category>Google Ads</category><category>Information Stealer</category></item><item><title>Operation FlutterBridge: New FlutterShell Backdoor Targets macOS</title><link>https://runtimerebel.com/blog/operation-flutterbridge-new-fluttershell-backdoor-targets-macos</link><guid isPermaLink="true">https://runtimerebel.com/blog/operation-flutterbridge-new-fluttershell-backdoor-targets-macos</guid><description>Researchers discover Operation FlutterBridge, a malvertising campaign delivering the FlutterShell backdoor to macOS users via Google and YouTube ads.</description><pubDate>Thu, 04 Jun 2026 13:15:08 GMT</pubDate><category>FlutterShell</category><category>Operation FlutterBridge</category><category>macOS Malware</category><category>JSCoreRunner</category><category>Malvertising</category></item><item><title>DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware</title><link>https://runtimerebel.com/blog/drivesurge-hijacking-thousands-of-sites-for-clickfix-fakeupdate-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/drivesurge-hijacking-thousands-of-sites-for-clickfix-fakeupdate-malware</guid><description>DriveSurge, a wide-scale IAB operation, hijacks thousands of trusted websites using a malicious TDS, redirecting users to sites distributing ClickFix and FakeUpdate…</description><pubDate>Tue, 02 Jun 2026 21:11:42 GMT</pubDate><category>DriveSurge</category><category>TDS</category><category>ClickFix</category><category>FakeUpdate</category><category>SocGholish</category><category>Malvertising</category><category>Ad Hijacking</category></item><item><title>Trapdoor Android Ad Fraud: 455 Apps Generate 659M Daily Bid Requests</title><link>https://runtimerebel.com/blog/trapdoor-android-ad-fraud-455-apps-generate-659m-daily-bid-requests</link><guid isPermaLink="true">https://runtimerebel.com/blog/trapdoor-android-ad-fraud-455-apps-generate-659m-daily-bid-requests</guid><description>Researchers reveal the Trapdoor ad fraud scheme, involving 455 Android apps and 183 C2 domains generating over 600 million daily fraudulent bid requests.</description><pubDate>Tue, 19 May 2026 20:39:59 GMT</pubDate><category>Android</category><category>Ad Fraud</category><category>Trapdoor</category><category>HUMAN Satori</category><category>Malvertising</category></item><item><title>Claude.ai Malvertising: How Attackers Abuse Shared Chats for macOS Malware</title><link>https://runtimerebel.com/blog/claude-ai-malvertising-how-attackers-abuse-shared-chats-for-macos-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-ai-malvertising-how-attackers-abuse-shared-chats-for-macos-malware</guid><description>Threat actors are leveraging Google Ads and legitimate Claude.ai shared chats to distribute macOS infostealers, effectively bypassing traditional web filters.</description><pubDate>Sun, 10 May 2026 20:19:55 GMT</pubDate><category>macOS Malware</category><category>Claude AI</category><category>Google Ads</category><category>Malvertising</category><category>Infostealer</category><category>Cuckoo</category></item><item><title>MacSync Stealer Distributed via Malicious Homebrew Ad Campaign</title><link>https://runtimerebel.com/blog/macsync-stealer-distributed-via-malicious-homebrew-ad-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/macsync-stealer-distributed-via-malicious-homebrew-ad-campaign</guid><description>Malicious ads for Homebrew distribute MacSync Stealer, targeting macOS users. Threat actors leverage trusted software to deploy data-stealing malware.</description><pubDate>Fri, 01 May 2026 20:25:24 GMT</pubDate><category>MacSync Stealer</category><category>Homebrew</category><category>macOS</category><category>Malvertising</category><category>Data Theft</category></item><item><title>Google Deploys Gemini AI to Combat Malvertising and Brand Fraud</title><link>https://runtimerebel.com/blog/google-deploys-gemini-ai-to-combat-malvertising-and-brand-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-deploys-gemini-ai-to-combat-malvertising-and-brand-fraud</guid><description>Google expands the use of Gemini LLMs to detect sophisticated ad scams, blocking 5.5 billion ads and countering AI-generated brand impersonation tactics.</description><pubDate>Thu, 16 Apr 2026 16:38:55 GMT</pubDate><category>Google Gemini</category><category>Malvertising</category><category>Ad Safety</category><category>AI in Cybersecurity</category><category>Phishing</category></item><item><title>Mirax Android RAT: Bypassing Security via Malicious Meta Ads</title><link>https://runtimerebel.com/blog/mirax-android-rat-bypassing-security-via-malicious-meta-ads</link><guid isPermaLink="true">https://runtimerebel.com/blog/mirax-android-rat-bypassing-security-via-malicious-meta-ads</guid><description>Mirax Android RAT targets 220,000 users via Meta Ads, turning devices into SOCKS5 proxies. Learn to detect and mitigate this emerging mobile threat.</description><pubDate>Tue, 14 Apr 2026 12:29:17 GMT</pubDate><category>Mirax</category><category>Android RAT</category><category>Meta Ads</category><category>SOCKS5 Proxy</category><category>Malvertising</category></item><item><title>AitM Phishing Campaign Targets TikTok Business via Turnstile Evasion</title><link>https://runtimerebel.com/blog/aitm-phishing-campaign-targets-tiktok-business-via-turnstile-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/aitm-phishing-campaign-targets-tiktok-business-via-turnstile-evasion</guid><description>Security researchers have identified a sophisticated AitM phishing campaign using Cloudflare Turnstile to hijack TikTok for Business accounts for malvertising.</description><pubDate>Fri, 27 Mar 2026 16:23:55 GMT</pubDate><category>Tiktok</category><category>AitM</category><category>Phishing</category><category>Cloudflare Turnstile</category><category>Malvertising</category><category>Credential Hijacking</category></item><item><title>Tax Search Malvertising Deploys HwAudKiller to Blind EDR Solutions</title><link>https://runtimerebel.com/blog/tax-search-malvertising-deploys-hwaudkiller-to-blind-edr-solutions</link><guid isPermaLink="true">https://runtimerebel.com/blog/tax-search-malvertising-deploys-hwaudkiller-to-blind-edr-solutions</guid><description>U.S. taxpayers targeted by malvertising campaign delivering ScreenConnect and HwAudKiller to disable security software via vulnerable Huawei drivers.</description><pubDate>Tue, 24 Mar 2026 20:18:52 GMT</pubDate><category>Malvertising</category><category>HwAudKiller</category><category>Screenconnect</category><category>BYOVD</category><category>Google Ads</category></item><item><title>InstallFix Attacks: Malvertising Spreads Fake Claude AI Code</title><link>https://runtimerebel.com/blog/installfix-attacks-malvertising-spreads-fake-claude-ai-code</link><guid isPermaLink="true">https://runtimerebel.com/blog/installfix-attacks-malvertising-spreads-fake-claude-ai-code</guid><description>InstallFix attacks leverage malvertising and ClickFix-style techniques to spread fake Claude AI code, targeting users of coding assistants and CLI operations.</description><pubDate>Tue, 10 Mar 2026 00:32:56 GMT</pubDate><category>InstallFix</category><category>Malvertising</category><category>AI Security</category><category>Claude AI</category><category>Social Engineering</category><category>Software Supply Chain</category></item></channel></rss>