<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Persistence</title><description>Cybersecurity articles tagged #Persistence on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Notepad++ Plugin Abuse: LunchPoke Malware Establishes Persistence</title><link>https://runtimerebel.com/blog/notepad-plugin-abuse-lunchpoke-malware-establishes-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/notepad-plugin-abuse-lunchpoke-malware-establishes-persistence</guid><description>CERT-UA uncovers attacks where threat actors bundle malicious LunchPoke utility as a Notepad++ plugin for stealthy malware installation and persistence.</description><pubDate>Thu, 23 Jul 2026 17:27:43 GMT</pubDate><category>Notepad</category><category>LunchPoke</category><category>CERT UA</category><category>Malware</category><category>Persistence</category><category>Supply Chain Attack</category></item><item><title>CVE-2026-50522: SharePoint RCE Exploitation to Steal Machine Keys</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-exploitation-to-steal-machine-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-exploitation-to-steal-machine-keys</guid><description>Critical CVE-2026-50522 in Microsoft SharePoint is actively exploited to steal machine keys, enabling persistent access. Understand the threat and mitigation.</description><pubDate>Tue, 21 Jul 2026 21:12:05 GMT</pubDate><category>CVE-2026-50522</category><category>SharePoint</category><category>RCE</category><category>Machine Keys</category><category>Persistence</category><category>Microsoft</category></item><item><title>ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops</title><link>https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</link><guid isPermaLink="true">https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</guid><description>ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.</description><pubDate>Thu, 16 Jul 2026 14:03:10 GMT</pubDate><category>macOS</category><category>Infostealer</category><category>ClickLock</category><category>Social Engineering</category><category>Persistence</category></item><item><title>Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT</title><link>https://runtimerebel.com/blog/analysis-of-obfuscated-powershell-loaders-delivering-remcos-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-obfuscated-powershell-loaders-delivering-remcos-rat</guid><description>Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.</description><pubDate>Tue, 23 Jun 2026 09:29:44 GMT</pubDate><category>Remcos RAT</category><category>PowerShell</category><category>Malware Loader</category><category>Persistence</category></item><item><title>Junior Hacker&apos;s Tailscale &amp; OpenSSH Post-C2 Persistence</title><link>https://runtimerebel.com/blog/junior-hacker-s-tailscale-openssh-post-c2-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/junior-hacker-s-tailscale-openssh-post-c2-persistence</guid><description>Analysis of a junior hacker&apos;s TTPs, leveraging Tailscale and OpenSSH for persistent access to a French automotive business after their Havoc C2 server went offline.</description><pubDate>Wed, 17 Jun 2026 17:07:49 GMT</pubDate><category>Tailscale</category><category>OpenSSH</category><category>Persistence</category><category>Havoc C2</category><category>Automotive Sector</category><category>Keylogger</category></item><item><title>OpenClaw &apos;Claw Chain&apos; Vulnerabilities: Credential Theft, Persistence</title><link>https://runtimerebel.com/blog/openclaw-claw-chain-vulnerabilities-credential-theft-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-claw-chain-vulnerabilities-credential-theft-persistence</guid><description>Analysis of &apos;Claw Chain&apos; vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks.</description><pubDate>Tue, 19 May 2026 00:58:13 GMT</pubDate><category>OpenClaw</category><category>AI Agent Framework</category><category>Claw Chain</category><category>Credential Theft</category><category>Privilege Escalation</category><category>Persistence</category><category>Application Security</category></item><item><title>Active Directory Post-Breach Persistence: Why Password Resets Fail</title><link>https://runtimerebel.com/blog/active-directory-post-breach-persistence-why-password-resets-fail</link><guid isPermaLink="true">https://runtimerebel.com/blog/active-directory-post-breach-persistence-why-password-resets-fail</guid><description>Explaining why password resets fail to evict attackers from Active Directory due to Kerberos ticket persistence and MSV1_0 credential caching mechanisms.</description><pubDate>Mon, 11 May 2026 17:01:15 GMT</pubDate><category>Active Directory</category><category>Kerberos</category><category>Persistence</category><category>Krbtgt</category><category>Incident Response</category></item><item><title>UNC6692 Targets Microsoft Teams to Deploy Snow Malware</title><link>https://runtimerebel.com/blog/unc6692-targets-microsoft-teams-to-deploy-snow-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6692-targets-microsoft-teams-to-deploy-snow-malware</guid><description>UNC6692 is leveraging Microsoft Teams and social engineering to deliver the modular Snow malware suite, facilitating long-term persistence and data theft.</description><pubDate>Sat, 25 Apr 2026 16:17:06 GMT</pubDate><category>UNC6692</category><category>Microsoft Teams</category><category>SNOW Malware</category><category>Social Engineering</category><category>Backdoor</category><category>Persistence</category></item><item><title>FIRESTARTER Backdoor Exploits Cisco Firepower ASA Software</title><link>https://runtimerebel.com/blog/firestarter-backdoor-exploits-cisco-firepower-asa-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/firestarter-backdoor-exploits-cisco-firepower-asa-software</guid><description>CISA and NCSC reveal FIRESTARTER, a persistent backdoor targeting Cisco Firepower devices running ASA software, used in federal agency compromises.</description><pubDate>Sat, 25 Apr 2026 00:42:32 GMT</pubDate><category>Cisco Firepower</category><category>Firestarter Malware</category><category>CISA Advisory</category><category>Asa Software</category><category>Persistence</category></item><item><title>Firestarter Backdoor Infects Cisco Firewall at US Federal Agency</title><link>https://runtimerebel.com/blog/firestarter-backdoor-infects-cisco-firewall-at-us-federal-agency</link><guid isPermaLink="true">https://runtimerebel.com/blog/firestarter-backdoor-infects-cisco-firewall-at-us-federal-agency</guid><description>Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.</description><pubDate>Fri, 24 Apr 2026 12:34:34 GMT</pubDate><category>FIRESTARTER</category><category>Cisco Firewall</category><category>Backdoor</category><category>Federal Agency</category><category>Persistence</category><category>Remote Access</category></item><item><title>FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower &amp; Secure Firewall</title><link>https://runtimerebel.com/blog/firestarter-backdoor-persistent-threat-to-cisco-firepower-secure-firewall</link><guid isPermaLink="true">https://runtimerebel.com/blog/firestarter-backdoor-persistent-threat-to-cisco-firepower-secure-firewall</guid><description>CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.</description><pubDate>Thu, 23 Apr 2026 16:44:19 GMT</pubDate><category>FIRESTARTER</category><category>Cisco Firepower</category><category>Cisco Secure Firewall</category><category>Cisco ASA</category><category>Backdoor</category><category>APT</category><category>CVE-2025-20333</category><category>CVE-2025-20362</category><category>LINE VIPER</category><category>Persistence</category></item><item><title>Dragon Boss Adware Evolves: Scheduled Tasks &amp; Windows Defender Evasion</title><link>https://runtimerebel.com/blog/dragon-boss-adware-evolves-scheduled-tasks-windows-defender-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/dragon-boss-adware-evolves-scheduled-tasks-windows-defender-evasion</guid><description>Dragon Boss adware transforms into a persistent AV killer, using scheduled tasks to establish presence and disable Windows Defender protections on infected systems.</description><pubDate>Fri, 17 Apr 2026 00:45:20 GMT</pubDate><category>Dragon Boss</category><category>Adware</category><category>AV Evasion</category><category>Windows Defender</category><category>Persistence</category><category>Scheduled Tasks</category></item><item><title>Detecting Malicious Web Shells: Analysis of Persistence and TTPs</title><link>https://runtimerebel.com/blog/detecting-malicious-web-shells-analysis-of-persistence-and-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-malicious-web-shells-analysis-of-persistence-and-ttps</guid><description>Discover how attackers use deceptive naming and pre-set credentials in web shells to maintain persistence and how to detect these malicious files on servers.</description><pubDate>Wed, 08 Apr 2026 08:35:56 GMT</pubDate><category>Web Shells</category><category>Persistence</category><category>Rce Exploitation</category><category>Incident Response</category></item><item><title>WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems</title><link>https://runtimerebel.com/blog/whatsapp-vbs-malware-bypasses-uac-to-hijack-windows-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/whatsapp-vbs-malware-bypasses-uac-to-hijack-windows-systems</guid><description>Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…</description><pubDate>Wed, 01 Apr 2026 16:25:50 GMT</pubDate><category>WhatsApp</category><category>VBScript</category><category>UAC Bypass</category><category>Windows</category><category>Malware</category><category>Persistence</category><category>Remote Access</category></item><item><title>Telecom Sleeper Cells and LLM Jailbreak Trends: Weekly Analysis</title><link>https://runtimerebel.com/blog/telecom-sleeper-cells-and-llm-jailbreak-trends-weekly-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/telecom-sleeper-cells-and-llm-jailbreak-trends-weekly-analysis</guid><description>An analysis of long-term persistence in telecom networks, LLM jailbreak methodologies, and regulatory shifts in UK age verification for Apple users.</description><pubDate>Mon, 30 Mar 2026 16:26:48 GMT</pubDate><category>Telecom Security</category><category>LLM Jailbreak</category><category>Persistence</category><category>Regulatory Compliance</category><category>Apple</category></item><item><title>GSocket Backdoor Analysis: Malicious Bash Script Delivery and Impact</title><link>https://runtimerebel.com/blog/gsocket-backdoor-analysis-malicious-bash-script-delivery-and-impact</link><guid isPermaLink="true">https://runtimerebel.com/blog/gsocket-backdoor-analysis-malicious-bash-script-delivery-and-impact</guid><description>Analysis of a malicious Bash script deploying the GSocket backdoor for persistent access, bypassing firewalls through advanced NAT traversal techniques.</description><pubDate>Fri, 20 Mar 2026 12:19:53 GMT</pubDate><category>Gsocket</category><category>Bash Malware</category><category>Persistence</category><category>Linux Security</category><category>Nat Traversal</category></item><item><title>Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access</title><link>https://runtimerebel.com/blog/hive0163-deploys-ai-assisted-slopoly-malware-for-persistent-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/hive0163-deploys-ai-assisted-slopoly-malware-for-persistent-access</guid><description>The Hive0163 threat actor is leveraging Slopoly, an AI-generated malware framework, to maintain persistence in ransomware campaigns and financial theft operations.</description><pubDate>Thu, 12 Mar 2026 20:13:13 GMT</pubDate><category>Hive0163</category><category>Slopoly</category><category>AI Assisted Malware</category><category>Ransomware</category><category>Persistence</category></item><item><title>BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement</title><link>https://runtimerebel.com/blog/byovd-driven-xmrig-campaign-employs-time-based-logic-bombs-and-lateral-movement</link><guid isPermaLink="true">https://runtimerebel.com/blog/byovd-driven-xmrig-campaign-employs-time-based-logic-bombs-and-lateral-movement</guid><description>An analysis of a sophisticated cryptojacking operation utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques and wormable components to maximize Monero mining…</description><pubDate>Mon, 23 Feb 2026 20:18:27 GMT</pubDate><category>XMRig</category><category>BYOVD</category><category>Cryptojacking</category><category>Persistence</category><category>Wormable</category></item></channel></rss>