<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Malware Delivery</title><description>Cybersecurity articles tagged #Malware Delivery on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Node.js Abuse: Attackers Deploy Malware via Trusted Runtime</title><link>https://runtimerebel.com/blog/node-js-abuse-attackers-deploy-malware-via-trusted-runtime</link><guid isPermaLink="true">https://runtimerebel.com/blog/node-js-abuse-attackers-deploy-malware-via-trusted-runtime</guid><description>Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.</description><pubDate>Thu, 03 Sep 2026 12:22:47 GMT</pubDate><category>Node Js</category><category>Malware Delivery</category><category>ClickFix</category><category>Living-off-the-Land</category><category>EtherHiding</category></item><item><title>New Phishing Campaign Exploits SVG Attachments to Evade Filters</title><link>https://runtimerebel.com/blog/new-phishing-campaign-exploits-svg-attachments-to-evade-filters</link><guid isPermaLink="true">https://runtimerebel.com/blog/new-phishing-campaign-exploits-svg-attachments-to-evade-filters</guid><description>Security researchers report a wave of phishing emails using malicious SVG attachments to deliver scripts and bypass email security gateways. Learn how to defend.</description><pubDate>Tue, 02 Jun 2026 09:35:03 GMT</pubDate><category>Phishing</category><category>SVG</category><category>Malware Delivery</category><category>Social Engineering</category><category>Email Security</category></item><item><title>AI Chatbot Poisoning: Defending Against Malicious Cryptojacking Links</title><link>https://runtimerebel.com/blog/ai-chatbot-poisoning-defending-against-malicious-cryptojacking-links</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-chatbot-poisoning-defending-against-malicious-cryptojacking-links</guid><description>Microsoft warns of threat actors manipulating AI chatbot recommendations to deliver cryptojacking malware via poisoned web search results.</description><pubDate>Wed, 27 May 2026 09:16:19 GMT</pubDate><category>Cryptojacking</category><category>AI Security</category><category>Social Engineering</category><category>Microsoft Defender</category><category>Malware Delivery</category></item><item><title>Abuse of MSHTA in Stealthy Malware Delivery Chains</title><link>https://runtimerebel.com/blog/abuse-of-mshta-in-stealthy-malware-delivery-chains</link><guid isPermaLink="true">https://runtimerebel.com/blog/abuse-of-mshta-in-stealthy-malware-delivery-chains</guid><description>Attackers are abusing the legacy Windows MSHTA utility to deliver malware silently via phishing and fake downloads, bypassing EDR through LOLBIN techniques.</description><pubDate>Tue, 19 May 2026 13:20:43 GMT</pubDate><category>Mshta</category><category>Lolbin</category><category>Phishing</category><category>Malware Delivery</category><category>Stealth Attacks</category></item><item><title>Malware Delivery via Malicious .WAV Files — Technical Analysis</title><link>https://runtimerebel.com/blog/malware-delivery-via-malicious-wav-files-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/malware-delivery-via-malicious-wav-files-technical-analysis</guid><description>Security analysts identify .WAV audio files being used to hide malicious payloads. Learn how steganography allows attackers to bypass perimeter security.</description><pubDate>Tue, 21 Apr 2026 08:45:41 GMT</pubDate><category>Steganography</category><category>Wav Malware</category><category>Powershell Obfuscation</category><category>APT32</category><category>Malware Delivery</category></item><item><title>Abused n8n Webhooks Facilitate Automated Malware Delivery Since 2025</title><link>https://runtimerebel.com/blog/abused-n8n-webhooks-facilitate-automated-malware-delivery-since-2025</link><guid isPermaLink="true">https://runtimerebel.com/blog/abused-n8n-webhooks-facilitate-automated-malware-delivery-since-2025</guid><description>Threat actors are weaponizing n8n AI workflow automation webhooks to bypass email filters and distribute malware in persistent phishing campaigns.</description><pubDate>Wed, 15 Apr 2026 20:22:35 GMT</pubDate><category>N8n</category><category>Phishing</category><category>Webhooks</category><category>Malware Delivery</category><category>Automation Abuse</category></item><item><title>ZIP Archive Evasion: Detecting Malicious Multi-File Payloads</title><link>https://runtimerebel.com/blog/zip-archive-evasion-detecting-malicious-multi-file-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/zip-archive-evasion-detecting-malicious-multi-file-payloads</guid><description>Analyze how threat actors use ZIP archives containing over 100,000 files to bypass security inspection and overwhelm automated analysis tools.</description><pubDate>Fri, 27 Mar 2026 04:52:03 GMT</pubDate><category>Evasion Techniques</category><category>Malware Delivery</category><category>ZIP Archives</category><category>Email Security</category></item><item><title>CVE-2026-0866: Mitigating Zombie Zip File Evasion Techniques</title><link>https://runtimerebel.com/blog/cve-2026-0866-mitigating-zombie-zip-file-evasion-techniques</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-0866-mitigating-zombie-zip-file-evasion-techniques</guid><description>Technical analysis of CVE-2026-0866 &apos;Zombie Zip&apos; exploitation. Learn how archive header discrepancies bypass security scanners and how to defend your perimeter.</description><pubDate>Wed, 11 Mar 2026 12:23:06 GMT</pubDate><category>CVE-2026-0866</category><category>Zombie Zip</category><category>Archive Evasion</category><category>Malware Delivery</category><category>Evasion TTPs</category></item></channel></rss>