<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Malware Analysis</title><description>Cybersecurity articles tagged #Malware Analysis on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws</title><link>https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</guid><description>Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.</description><pubDate>Tue, 01 Sep 2026 02:51:10 GMT</pubDate><category>Phishing</category><category>Credential Theft</category><category>Obfuscation</category><category>JavaScript</category><category>Malware Analysis</category></item><item><title>State of AI-Enabled Malware: Real-World Impact and Defenses</title><link>https://runtimerebel.com/blog/state-of-ai-enabled-malware-real-world-impact-and-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/state-of-ai-enabled-malware-real-world-impact-and-defenses</guid><description>Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.</description><pubDate>Tue, 25 Aug 2026 16:29:19 GMT</pubDate><category>LLM</category><category>Ransomware</category><category>Malware Analysis</category><category>Social Engineering</category><category>AI Enabled Malware</category></item><item><title>AI-Powered Malware Analysis: Detecting Persistent Threats on Sensors</title><link>https://runtimerebel.com/blog/ai-powered-malware-analysis-detecting-persistent-threats-on-sensors</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-malware-analysis-detecting-persistent-threats-on-sensors</guid><description>An analysis using Gemma4 with Ollama reveals high-volume malware downloads on DShield sensors, indicating persistent actor activity and critical compromise risks.</description><pubDate>Thu, 13 Aug 2026 09:04:55 GMT</pubDate><category>AI</category><category>Malware Analysis</category><category>Threat Hunting</category><category>Botnet</category><category>Cowrie Sensor</category></item><item><title>Recorded Future&apos;s Engine: Unifying Threat Intelligence Sources</title><link>https://runtimerebel.com/blog/recorded-future-s-engine-unifying-threat-intelligence-sources</link><guid isPermaLink="true">https://runtimerebel.com/blog/recorded-future-s-engine-unifying-threat-intelligence-sources</guid><description>Explore Recorded Future&apos;s unique collection engine, integrating technical, underground, and community intelligence for proactive threat defense and deeper insights.</description><pubDate>Sat, 08 Aug 2026 01:02:37 GMT</pubDate><category>Threat Intelligence</category><category>Data Collection</category><category>Malware Analysis</category><category>Vulnerability Management</category><category>Recorded Future</category></item><item><title>Analyzing AutoIT Payload Injection Techniques in Modern Malware</title><link>https://runtimerebel.com/blog/analyzing-autoit-payload-injection-techniques-in-modern-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/analyzing-autoit-payload-injection-techniques-in-modern-malware</guid><description>Technical analysis of how threat actors use AutoIT scripts for process injection, leveraging memory management functions to execute malicious payloads in memory.</description><pubDate>Tue, 28 Jul 2026 10:39:31 GMT</pubDate><category>AutoIT</category><category>Process Injection</category><category>Memory Forensics</category><category>Malware Analysis</category></item><item><title>Dolphin X Malware: AI-Driven Target Prioritization &amp; Defense</title><link>https://runtimerebel.com/blog/dolphin-x-malware-ai-driven-target-prioritization-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/dolphin-x-malware-ai-driven-target-prioritization-defense</guid><description>Analysis of Dolphin X, a new RAT utilizing AI to profile and rank victims, enabling threat actors to prioritize high-value targets for data exfiltration and further…</description><pubDate>Fri, 24 Jul 2026 02:46:46 GMT</pubDate><category>DolphinX</category><category>RAT</category><category>AI</category><category>Targeting</category><category>Malware Analysis</category><category>Cyber Threat</category></item><item><title>AI Models Fail at Nuclear Sabotage Malware Analysis Benchmark</title><link>https://runtimerebel.com/blog/ai-models-fail-at-nuclear-sabotage-malware-analysis-benchmark</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-models-fail-at-nuclear-sabotage-malware-analysis-benchmark</guid><description>New SentinelOne research reveals frontier AI models struggle with complex malware investigations, particularly those involving nuclear sabotage and industrial systems.</description><pubDate>Thu, 23 Jul 2026 14:13:02 GMT</pubDate><category>AI Security</category><category>Fast16</category><category>SentinelOne</category><category>Malware Analysis</category><category>ICS Security</category></item><item><title>Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users</title><link>https://runtimerebel.com/blog/ousaban-banking-trojan-phishing-lures-target-iberian-bank-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/ousaban-banking-trojan-phishing-lures-target-iberian-bank-users</guid><description>Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.</description><pubDate>Wed, 01 Jul 2026 16:53:05 GMT</pubDate><category>Ousaban</category><category>Banking Trojan</category><category>Phishing</category><category>Spain</category><category>Portugal</category><category>Windows</category><category>Financial Crime</category><category>Malware Analysis</category></item><item><title>YARA-X 1.18.0 &amp; 1.19.0 Release: Enhancing Malware Detection</title><link>https://runtimerebel.com/blog/yara-x-1-18-0-1-19-0-release-enhancing-malware-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/yara-x-1-18-0-1-19-0-release-enhancing-malware-detection</guid><description>YARA-X versions 1.18.0 and 1.19.0 bring key improvements and bug fixes, enhancing malware analysis and threat hunting capabilities for security professionals.</description><pubDate>Sun, 28 Jun 2026 09:09:21 GMT</pubDate><category>YARA X</category><category>Malware Analysis</category><category>Threat Hunting</category><category>Security Tools</category><category>Version Update</category></item><item><title>Malware Evades AI Analysis with &apos;Forbidden Text&apos; Tactics</title><link>https://runtimerebel.com/blog/malware-evades-ai-analysis-with-forbidden-text-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/malware-evades-ai-analysis-with-forbidden-text-tactics</guid><description>Threat actors embed &apos;forbidden&apos; text in malware to confuse AI analysis tools, targeting bioinformatics and MCP developers.</description><pubDate>Thu, 25 Jun 2026 05:28:25 GMT</pubDate><category>AI Evasion</category><category>Malware Analysis</category><category>Mini Shai Hulud</category><category>Miasma</category><category>Hades Worms</category><category>Bioinformatics Security</category><category>Supply Chain Security</category></item><item><title>MSI Malware Detection: Statistical Analysis for Base64 Payloads</title><link>https://runtimerebel.com/blog/msi-malware-detection-statistical-analysis-for-base64-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/msi-malware-detection-statistical-analysis-for-base64-payloads</guid><description>Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.</description><pubDate>Mon, 15 Jun 2026 10:19:14 GMT</pubDate><category>MSI Malware</category><category>Base64 Obfuscation</category><category>Threat Detection</category><category>Malware Analysis</category><category>SANS ISC</category></item><item><title>Python-Based Infostealer Masked as PDF Targets Browser Credentials</title><link>https://runtimerebel.com/blog/python-based-infostealer-masked-as-pdf-targets-browser-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/python-based-infostealer-masked-as-pdf-targets-browser-credentials</guid><description>Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.</description><pubDate>Tue, 09 Jun 2026 09:19:02 GMT</pubDate><category>Infostealer</category><category>Pyinstaller</category><category>Discord Webhook</category><category>Credential Theft</category><category>Malware Analysis</category></item><item><title>WordPress Sites Targeted by Malware Using Steam Profile Dead-Drops</title><link>https://runtimerebel.com/blog/wordpress-sites-targeted-by-malware-using-steam-profile-dead-drops</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-sites-targeted-by-malware-using-steam-profile-dead-drops</guid><description>Over 2,000 WordPress sites compromised in a campaign hiding C2 resolution data within Steam Community profiles. Technical breakdown of the evasion tactics.</description><pubDate>Mon, 01 Jun 2026 18:06:43 GMT</pubDate><category>WordPress</category><category>Steam Community</category><category>C2 Evasion</category><category>Steganography</category><category>Malware Analysis</category></item><item><title>NetSupport RAT Infection: How to Detect Unidentified Loader Exploits</title><link>https://runtimerebel.com/blog/netsupport-rat-infection-how-to-detect-unidentified-loader-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/netsupport-rat-infection-how-to-detect-unidentified-loader-exploits</guid><description>Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.</description><pubDate>Mon, 01 Jun 2026 01:04:07 GMT</pubDate><category>NetSupport RAT</category><category>Malware Analysis</category><category>PowerShell</category><category>JavaScript</category><category>Loader</category></item><item><title>Obfuscating Strings in C++ Implants: Detection and Analysis</title><link>https://runtimerebel.com/blog/obfuscating-strings-in-c-implants-detection-and-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/obfuscating-strings-in-c-implants-detection-and-analysis</guid><description>Analyze how stack strings help malware authors evade static analysis. Explore the assembly-level mechanics and detection strategies for Windows implants.</description><pubDate>Sat, 23 May 2026 08:48:07 GMT</pubDate><category>Stack Strings</category><category>Obfuscation</category><category>Windows Implants</category><category>Red Teaming</category><category>Malware Analysis</category></item><item><title>Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments</title><link>https://runtimerebel.com/blog/shai-hulud-worm-code-leak-how-clones-threaten-developer-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-worm-code-leak-how-clones-threaten-developer-environments</guid><description>The release of Shai-Hulud worm source code triggers a surge in self-replicating clones, targeting software developers and automated CI/CD pipelines.</description><pubDate>Mon, 18 May 2026 20:37:43 GMT</pubDate><category>Shai Hulud</category><category>Worm</category><category>Developer Security</category><category>Source Code Leak</category><category>Malware Analysis</category></item><item><title>Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns</title><link>https://runtimerebel.com/blog/masjesu-botnet-ddos-for-hire-analysis-of-iot-malware-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/masjesu-botnet-ddos-for-hire-analysis-of-iot-malware-campaigns</guid><description>The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.</description><pubDate>Wed, 08 Apr 2026 20:18:14 GMT</pubDate><category>Masjesu Botnet</category><category>DDoS</category><category>Iot Security</category><category>Malware Analysis</category><category>Telegram Botnet</category></item><item><title>Fileless Malware Registry Persistence Techniques Exposed</title><link>https://runtimerebel.com/blog/fileless-malware-registry-persistence-techniques-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/fileless-malware-registry-persistence-techniques-exposed</guid><description>Analyzes how fileless malware leverages the Windows registry for persistence, minimizing filesystem footprint and complicating traditional detection.</description><pubDate>Wed, 01 Apr 2026 12:30:01 GMT</pubDate><category>Fileless Malware</category><category>Registry Persistence</category><category>TTPs</category><category>Malware Analysis</category><category>Detection</category><category>Windows Registry</category></item><item><title>PDF Incremental Updates: Detecting Hidden Malicious URLs</title><link>https://runtimerebel.com/blog/pdf-incremental-updates-detecting-hidden-malicious-urls</link><guid isPermaLink="true">https://runtimerebel.com/blog/pdf-incremental-updates-detecting-hidden-malicious-urls</guid><description>Discover how attackers use PDF incremental updates to obfuscate malicious URLs and learn forensic techniques to identify and extract hidden indicators.</description><pubDate>Mon, 30 Mar 2026 05:02:33 GMT</pubDate><category>PDF Malware</category><category>Didier Stevens</category><category>Forensics</category><category>Malware Analysis</category><category>Phishing Detection</category></item><item><title>GlassWorm Supply Chain Attack: 400+ Malicious Repos Identified</title><link>https://runtimerebel.com/blog/glassworm-supply-chain-attack-400-malicious-repos-identified</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-supply-chain-attack-400-malicious-repos-identified</guid><description>The GlassWorm campaign hits GitHub, npm, and VSCode marketplaces with over 400 malicious repositories. Learn to detect and mitigate this supply chain threat.</description><pubDate>Wed, 18 Mar 2026 00:36:52 GMT</pubDate><category>GlassWorm</category><category>NPM Security</category><category>Vscode Extensions</category><category>Supply Chain Attack</category><category>Malware Analysis</category></item><item><title>Analyzing Embedded ZIP Payloads in RTF Documents for Malware Analysis</title><link>https://runtimerebel.com/blog/analyzing-embedded-zip-payloads-in-rtf-documents-for-malware-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/analyzing-embedded-zip-payloads-in-rtf-documents-for-malware-analysis</guid><description>Learn how to detect ZIP files in RTF documents and extract hex-encoded binary payloads using specialized forensic tools to identify hidden malware threats.</description><pubDate>Mon, 02 Mar 2026 12:19:41 GMT</pubDate><category>RTF</category><category>ZIP Extraction</category><category>Malware Analysis</category><category>Didier Stevens</category><category>Forensics</category></item></channel></rss>