<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Obfuscation</title><description>Cybersecurity articles tagged #Obfuscation on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws</title><link>https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/polymorphic-phishing-page-analysis-javascript-obfuscation-flaws</guid><description>Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.</description><pubDate>Tue, 01 Sep 2026 02:51:10 GMT</pubDate><category>Phishing</category><category>Credential Theft</category><category>Obfuscation</category><category>JavaScript</category><category>Malware Analysis</category></item><item><title>Deobfuscating Malicious JavaScript for Threat Analysis</title><link>https://runtimerebel.com/blog/deobfuscating-malicious-javascript-for-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/deobfuscating-malicious-javascript-for-threat-analysis</guid><description>Understanding JavaScript obfuscation techniques used in phishing and malware. Learn static and dynamic deobfuscation methods to uncover malicious intent.</description><pubDate>Tue, 01 Sep 2026 02:45:47 GMT</pubDate><category>JavaScript</category><category>Obfuscation</category><category>Phishing</category><category>Malware</category><category>Deobfuscation</category></item><item><title>Detecting SSRF Hostname Obfuscation: 1u.ms and Cloud Metadata</title><link>https://runtimerebel.com/blog/detecting-ssrf-hostname-obfuscation-1u-ms-and-cloud-metadata</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-ssrf-hostname-obfuscation-1u-ms-and-cloud-metadata</guid><description>Attackers are leveraging hostnames and services like 1u.ms to obfuscate IP addresses (e.g., 169.254.169.254), bypassing traditional SSRF blocklist defenses.</description><pubDate>Tue, 25 Aug 2026 16:30:00 GMT</pubDate><category>SSRF</category><category>Obfuscation</category><category>Cloud Security</category><category>Threat Intelligence</category><category>1u Ms</category></item><item><title>WordlistLoader Evades Detection, Delivers Amatera Infostealer</title><link>https://runtimerebel.com/blog/wordlistloader-evades-detection-delivers-amatera-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordlistloader-evades-detection-delivers-amatera-infostealer</guid><description>WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.</description><pubDate>Tue, 25 Aug 2026 08:33:21 GMT</pubDate><category>Infostealer</category><category>Malware</category><category>Obfuscation</category><category>ClickFix</category><category>WordlistLoader</category></item><item><title>Text Salting: Hidden Text Tactics Bypass AI Email Filters</title><link>https://runtimerebel.com/blog/text-salting-hidden-text-tactics-bypass-ai-email-filters</link><guid isPermaLink="true">https://runtimerebel.com/blog/text-salting-hidden-text-tactics-bypass-ai-email-filters</guid><description>Over 1 million emails are leveraging text salting techniques, embedding hidden characters to bypass AI and LLM-based email security filters, posing a significant…</description><pubDate>Thu, 16 Jul 2026 21:02:58 GMT</pubDate><category>Text Salting</category><category>Phishing</category><category>AI Security</category><category>Email Security</category><category>LLMs</category><category>Obfuscation</category></item><item><title>Linux Process Name Masquerading: Analyzing T1036 Obfuscation</title><link>https://runtimerebel.com/blog/linux-process-name-masquerading-analyzing-t1036-obfuscation</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-process-name-masquerading-analyzing-t1036-obfuscation</guid><description>Explore the technical methods behind Linux process name masquerading (MITRE ATT&amp;CK T1036) used by actors like Velvet Ant to evade detection.</description><pubDate>Wed, 24 Jun 2026 09:23:19 GMT</pubDate><category>T1036</category><category>Linux Security</category><category>Velvet Ant</category><category>Process Masquerading</category><category>Obfuscation</category></item><item><title>Excel VBA Macro Obfuscation: How to Detect Hidden Payloads</title><link>https://runtimerebel.com/blog/excel-vba-macro-obfuscation-how-to-detect-hidden-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/excel-vba-macro-obfuscation-how-to-detect-hidden-payloads</guid><description>Learn how to analyze and detect obfuscated VBA macros in Excel files using oledump.py. Technical guide on character substitution and string reversal techniques.</description><pubDate>Mon, 08 Jun 2026 05:41:41 GMT</pubDate><category>VBA</category><category>Excel</category><category>Oledump</category><category>Obfuscation</category><category>Phishing</category></item><item><title>Obfuscating Strings in C++ Implants: Detection and Analysis</title><link>https://runtimerebel.com/blog/obfuscating-strings-in-c-implants-detection-and-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/obfuscating-strings-in-c-implants-detection-and-analysis</guid><description>Analyze how stack strings help malware authors evade static analysis. Explore the assembly-level mechanics and detection strategies for Windows implants.</description><pubDate>Sat, 23 May 2026 08:48:07 GMT</pubDate><category>Stack Strings</category><category>Obfuscation</category><category>Windows Implants</category><category>Red Teaming</category><category>Malware Analysis</category></item><item><title>Analysis of Cross-Platform NPM Stealer Using Discord Webhooks</title><link>https://runtimerebel.com/blog/analysis-of-cross-platform-npm-stealer-using-discord-webhooks</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-cross-platform-npm-stealer-using-discord-webhooks</guid><description>Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.</description><pubDate>Fri, 22 May 2026 09:17:57 GMT</pubDate><category>NPM</category><category>Node Js</category><category>Infostealer</category><category>Discord Webhook</category><category>Obfuscation</category></item><item><title>Malicious PDF Structure Analysis and Obfuscation Detection</title><link>https://runtimerebel.com/blog/malicious-pdf-structure-analysis-and-obfuscation-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-pdf-structure-analysis-and-obfuscation-detection</guid><description>Learn how to detect malicious PDF obfuscation and analyze internal structures like /OpenAction and /JS streams to identify hidden malware payloads.</description><pubDate>Thu, 21 May 2026 09:17:24 GMT</pubDate><category>PDF Malware</category><category>Obfuscation</category><category>Phishing Analysis</category><category>Malware Detection</category></item><item><title>Detect Obfuscated JavaScript Phishing Delivered via RAR Archives</title><link>https://runtimerebel.com/blog/detect-obfuscated-javascript-phishing-delivered-via-rar-archives</link><guid isPermaLink="true">https://runtimerebel.com/blog/detect-obfuscated-javascript-phishing-delivered-via-rar-archives</guid><description>Security researchers identify a new phishing campaign using heavily obfuscated JavaScript within RAR archives to bypass traditional endpoint detection.</description><pubDate>Fri, 10 Apr 2026 08:43:36 GMT</pubDate><category>JavaScript</category><category>Phishing</category><category>RAR</category><category>Obfuscation</category><category>WScript</category><category>Evasion</category></item><item><title>Emoji-Based C2: Threat Actors Adopt Covert Communication Tactics</title><link>https://runtimerebel.com/blog/emoji-based-c2-threat-actors-adopt-covert-communication-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/emoji-based-c2-threat-actors-adopt-covert-communication-tactics</guid><description>Threat actors are increasingly using emojis for covert Command and Control communications to evade security filters. Learn how to detect these obfuscated TTPs.</description><pubDate>Thu, 09 Apr 2026 00:35:54 GMT</pubDate><category>Emoji</category><category>Covert Communication</category><category>C2</category><category>Threat Actor TTPs</category><category>Evasion</category><category>Obfuscation</category></item><item><title>DeepLoad Malware Leverages AI for Evasion and Credential Theft</title><link>https://runtimerebel.com/blog/deepload-malware-leverages-ai-for-evasion-and-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/deepload-malware-leverages-ai-for-evasion-and-credential-theft</guid><description>DeepLoad, an AI-powered malware, uses massive junk code to evade detection while stealing credentials. Learn its TTPs and mitigation strategies.</description><pubDate>Tue, 31 Mar 2026 00:40:33 GMT</pubDate><category>DeepLoad</category><category>AI Malware</category><category>Credential Theft</category><category>Evasion</category><category>Obfuscation</category></item><item><title>SVG-Based Phishing: Using Scalable Vector Graphics for Credential Theft</title><link>https://runtimerebel.com/blog/svg-based-phishing-using-scalable-vector-graphics-for-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/svg-based-phishing-using-scalable-vector-graphics-for-credential-theft</guid><description>Discover how threat actors leverage SVG files to bypass email filters and execute credential theft through embedded JavaScript and HTML forms.</description><pubDate>Wed, 25 Mar 2026 04:43:26 GMT</pubDate><category>SVG Phishing</category><category>Credential Theft</category><category>Email Security</category><category>Obfuscation</category></item><item><title>Exploiting IPv4-Mapped IPv6 Addresses to Obfuscate Web Scanning</title><link>https://runtimerebel.com/blog/exploiting-ipv4-mapped-ipv6-addresses-to-obfuscate-web-scanning</link><guid isPermaLink="true">https://runtimerebel.com/blog/exploiting-ipv4-mapped-ipv6-addresses-to-obfuscate-web-scanning</guid><description>Attackers leverage RFC 4038 IPv4-mapped IPv6 addresses to bypass security filters and obfuscate scanning activities targeting proxy-related URLs.</description><pubDate>Tue, 17 Mar 2026 12:32:56 GMT</pubDate><category>RFC 4038</category><category>IPv6 Transition</category><category>Web Scanning</category><category>Obfuscation</category><category>Log Normalization</category></item></channel></rss>