<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #PowerShell</title><description>Cybersecurity articles tagged #PowerShell on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Faronics Deploy Abused by Phishing Actors to Install ScreenConnect</title><link>https://runtimerebel.com/blog/faronics-deploy-abused-by-phishing-actors-to-install-screenconnect</link><guid isPermaLink="true">https://runtimerebel.com/blog/faronics-deploy-abused-by-phishing-actors-to-install-screenconnect</guid><description>Phishing actors are abusing the legitimate Faronics Deploy endpoint management tool to gain remote access and install ScreenConnect via malicious installers.</description><pubDate>Wed, 02 Sep 2026 01:58:12 GMT</pubDate><category>Screenconnect</category><category>Phishing</category><category>Remote Access Trojan</category><category>Huntress</category><category>PowerShell</category></item><item><title>TerminalFix: PowerShell Weaponization in Enterprise Attacks</title><link>https://runtimerebel.com/blog/terminalfix-powershell-weaponization-in-enterprise-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/terminalfix-powershell-weaponization-in-enterprise-attacks</guid><description>Analysis of &apos;TerminalFix&apos; campaign, detailing PowerShell weaponization, multistage attack chain, and reverse tunnels into enterprise networks.</description><pubDate>Tue, 01 Sep 2026 12:56:24 GMT</pubDate><category>TerminalFix</category><category>PowerShell</category><category>Reverse Tunnel</category><category>Enterprise Attacks</category><category>Threat Campaign</category></item><item><title>DOUBLECUP Malware: Appended PowerShell Payloads in PNG Files</title><link>https://runtimerebel.com/blog/doublecup-malware-appended-powershell-payloads-in-png-files</link><guid isPermaLink="true">https://runtimerebel.com/blog/doublecup-malware-appended-powershell-payloads-in-png-files</guid><description>Analysis of DOUBLECUP malware reveals a deceptive technique: appending cleartext PowerShell payloads to PNG image files, bypassing traditional steganography.</description><pubDate>Mon, 24 Aug 2026 08:39:29 GMT</pubDate><category>Malware</category><category>PowerShell</category><category>Steganography</category><category>Threat Intelligence</category><category>DOUBLECUP</category></item><item><title>Entra Log Analysis: Detecting Password Spray Attacks with PowerShell</title><link>https://runtimerebel.com/blog/entra-log-analysis-detecting-password-spray-attacks-with-powershell</link><guid isPermaLink="true">https://runtimerebel.com/blog/entra-log-analysis-detecting-password-spray-attacks-with-powershell</guid><description>Learn to analyze Microsoft Entra sign-in logs using PowerShell to detect password spray attacks and anomalous successful logins from unexpected geographic locations.</description><pubDate>Fri, 21 Aug 2026 08:33:19 GMT</pubDate><category>Entra ID</category><category>Azure AD</category><category>PowerShell</category><category>Threat Detection</category><category>Identity Access</category></item><item><title>Auditing Entra ID MFA Gaps with PowerShell and Microsoft Graph</title><link>https://runtimerebel.com/blog/auditing-entra-id-mfa-gaps-with-powershell-and-microsoft-graph</link><guid isPermaLink="true">https://runtimerebel.com/blog/auditing-entra-id-mfa-gaps-with-powershell-and-microsoft-graph</guid><description>A new PowerShell script helps security teams identify Microsoft Entra ID users not registered for MFA or using weaker authentication methods.</description><pubDate>Fri, 21 Aug 2026 08:32:39 GMT</pubDate><category>Microsoft Entra ID</category><category>MFA</category><category>PowerShell</category><category>Identity Access</category><category>Microsoft Graph</category></item><item><title>PowerShell and WMI Detection: Analyzing Suspicious Command Lines</title><link>https://runtimerebel.com/blog/powershell-and-wmi-detection-analyzing-suspicious-command-lines</link><guid isPermaLink="true">https://runtimerebel.com/blog/powershell-and-wmi-detection-analyzing-suspicious-command-lines</guid><description>Learn to detect obfuscated PowerShell commands and malicious WMI activity through advanced command-line monitoring and log analysis for security teams.</description><pubDate>Fri, 17 Jul 2026 06:18:20 GMT</pubDate><category>PowerShell</category><category>WMI</category><category>Command Line Analysis</category><category>Windows Security</category><category>Detection Engineering</category></item><item><title>Analyzing Remcos RAT Delivery via Malicious LNK Files</title><link>https://runtimerebel.com/blog/analyzing-remcos-rat-delivery-via-malicious-lnk-files</link><guid isPermaLink="true">https://runtimerebel.com/blog/analyzing-remcos-rat-delivery-via-malicious-lnk-files</guid><description>Technical analysis of how threat actors use deceptive LNK files and obfuscated PowerShell to deliver Remcos RAT, including detection and mitigation strategies.</description><pubDate>Mon, 13 Jul 2026 02:56:21 GMT</pubDate><category>Remcos</category><category>LNK</category><category>PowerShell</category><category>Phishing</category></item><item><title>Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot &amp; PowerShell</title><link>https://runtimerebel.com/blog/veil-drop-attacks-deploy-purelog-info-stealer-via-blogspot-powershell</link><guid isPermaLink="true">https://runtimerebel.com/blog/veil-drop-attacks-deploy-purelog-info-stealer-via-blogspot-powershell</guid><description>Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.</description><pubDate>Mon, 06 Jul 2026 21:40:18 GMT</pubDate><category>Veil Drop</category><category>PureLog</category><category>Information Stealer</category><category>Blogspot</category><category>PowerShell</category><category>Fileless Malware</category><category>Securonix</category></item><item><title>Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT</title><link>https://runtimerebel.com/blog/analysis-of-obfuscated-powershell-loaders-delivering-remcos-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-obfuscated-powershell-loaders-delivering-remcos-rat</guid><description>Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.</description><pubDate>Tue, 23 Jun 2026 09:29:44 GMT</pubDate><category>Remcos RAT</category><category>PowerShell</category><category>Malware Loader</category><category>Persistence</category></item><item><title>NetSupport RAT Infection: How to Detect Unidentified Loader Exploits</title><link>https://runtimerebel.com/blog/netsupport-rat-infection-how-to-detect-unidentified-loader-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/netsupport-rat-infection-how-to-detect-unidentified-loader-exploits</guid><description>Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.</description><pubDate>Mon, 01 Jun 2026 01:04:07 GMT</pubDate><category>NetSupport RAT</category><category>Malware Analysis</category><category>PowerShell</category><category>JavaScript</category><category>Loader</category></item><item><title>Weaponized Trust: Analyzing the Abuse of Administrative Utilities</title><link>https://runtimerebel.com/blog/weaponized-trust-analyzing-the-abuse-of-administrative-utilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/weaponized-trust-analyzing-the-abuse-of-administrative-utilities</guid><description>Research reveals how threat actors leverage legitimate tools like PowerShell and WMIC to bypass detection by masquerading as routine administration.</description><pubDate>Fri, 15 May 2026 12:44:24 GMT</pubDate><category>Living-off-the-Land</category><category>PowerShell</category><category>Wmic</category><category>Adversary Tactics</category><category>Bitdefender</category></item><item><title>PowMix Botnet Targets Czech Workers via Randomized C2 Traffic</title><link>https://runtimerebel.com/blog/powmix-botnet-targets-czech-workers-via-randomized-c2-traffic</link><guid isPermaLink="true">https://runtimerebel.com/blog/powmix-botnet-targets-czech-workers-via-randomized-c2-traffic</guid><description>Researchers uncover the PowMix botnet targeting the Czech workforce with evasive randomized C2 beaconing to bypass network signature detections.</description><pubDate>Thu, 16 Apr 2026 20:20:25 GMT</pubDate><category>PowMix</category><category>Botnet</category><category>Czech Republic</category><category>Cisco Talos</category><category>C2 Evasion</category><category>PowerShell</category></item><item><title>DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea</title><link>https://runtimerebel.com/blog/dprk-hackers-abuse-github-infrastructure-for-c2-in-south-korea</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-hackers-abuse-github-infrastructure-for-c2-in-south-korea</guid><description>North Korean state-sponsored actors are leveraging GitHub as a command-and-control platform in complex multi-stage attacks targeting South Korean organizations.</description><pubDate>Mon, 06 Apr 2026 20:17:41 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>GitHub C2</category><category>South Korea</category><category>LNK</category><category>PowerShell</category></item><item><title>SmartApeSG Campaign: Multi-RAT Distribution via Malicious Archives</title><link>https://runtimerebel.com/blog/smartapesg-campaign-multi-rat-distribution-via-malicious-archives</link><guid isPermaLink="true">https://runtimerebel.com/blog/smartapesg-campaign-multi-rat-distribution-via-malicious-archives</guid><description>Analysis of the SmartApeSG campaign leveraging phishing, LNK files, and scripts to distribute Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. Learn mitigation.</description><pubDate>Wed, 25 Mar 2026 04:43:52 GMT</pubDate><category>SmartApeSG</category><category>Remcos RAT</category><category>NetSupport RAT</category><category>StealC</category><category>Sectop RAT</category><category>Arechclient2</category><category>Phishing</category><category>LNK Files</category><category>PowerShell</category><category>VBScript</category></item><item><title>InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers</title><link>https://runtimerebel.com/blog/installfix-campaign-cloned-ai-tool-sites-distribute-info-stealers</link><guid isPermaLink="true">https://runtimerebel.com/blog/installfix-campaign-cloned-ai-tool-sites-distribute-info-stealers</guid><description>The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.</description><pubDate>Mon, 09 Mar 2026 12:19:23 GMT</pubDate><category>InstallFix</category><category>AI Tools</category><category>Lumma Stealer</category><category>PowerShell</category><category>Infostealer</category></item><item><title>XWorm RAT Delivery: Analyzing Multi-Stage Infection Chains</title><link>https://runtimerebel.com/blog/xworm-rat-delivery-analyzing-multi-stage-infection-chains</link><guid isPermaLink="true">https://runtimerebel.com/blog/xworm-rat-delivery-analyzing-multi-stage-infection-chains</guid><description>New XWorm malware waves utilize multi-technology delivery involving LNK files and PowerShell. Learn how to detect and mitigate XWorm RAT infections.</description><pubDate>Wed, 04 Mar 2026 12:21:50 GMT</pubDate><category>XWorm</category><category>Remote Access Trojan</category><category>PowerShell</category><category>Malicious LNK</category><category>VBScript</category></item><item><title>Trojanized Gaming Tools Deliver Java-Based RAT via PowerShell</title><link>https://runtimerebel.com/blog/trojanized-gaming-tools-deliver-java-based-rat-via-powershell</link><guid isPermaLink="true">https://runtimerebel.com/blog/trojanized-gaming-tools-deliver-java-based-rat-via-powershell</guid><description>Security researchers identify a malware campaign using trojanized gaming tools to deliver a Java-based RAT using PowerShell and portable Java runtimes.</description><pubDate>Fri, 27 Feb 2026 12:17:15 GMT</pubDate><category>Java RAT</category><category>PowerShell</category><category>Social Engineering</category><category>Malicious Downloader</category><category>Gaming Utilities</category><category>JRE Staging</category></item></channel></rss>