<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #RAT</title><description>Cybersecurity articles tagged #RAT on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>FTP Banners Abused to Deliver E4del and PINHOLE RATs</title><link>https://runtimerebel.com/blog/ftp-banners-abused-to-deliver-e4del-and-pinhole-rats</link><guid isPermaLink="true">https://runtimerebel.com/blog/ftp-banners-abused-to-deliver-e4del-and-pinhole-rats</guid><description>Threat actors are using FTP server banners to hide commands, delivering new Windows remote access trojans E4del and PINHOLE via LNK-based infection chains.</description><pubDate>Mon, 24 Aug 2026 08:38:06 GMT</pubDate><category>RAT</category><category>LNK Files</category><category>Phishing</category><category>E4del</category><category>PINHOLE</category></item><item><title>SilkParasite Espionage Campaign Targets Central Asian Governments</title><link>https://runtimerebel.com/blog/silkparasite-espionage-campaign-targets-central-asian-governments</link><guid isPermaLink="true">https://runtimerebel.com/blog/silkparasite-espionage-campaign-targets-central-asian-governments</guid><description>SilkParasite espionage campaign targets Central Asian governments with seven remote access tools, including five newly documented RAT families.</description><pubDate>Wed, 19 Aug 2026 16:20:56 GMT</pubDate><category>Espionage</category><category>RAT</category><category>Malware</category><category>SilkParasite</category><category>ShadowPad</category></item><item><title>msaRAT: Chaos Ransomware&apos;s Covert Browser-Based C2</title><link>https://runtimerebel.com/blog/msarat-chaos-ransomware-s-covert-browser-based-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/msarat-chaos-ransomware-s-covert-browser-based-c2</guid><description>Cisco Talos uncovers msaRAT, a new Rust-based RAT used by Chaos ransomware for covert C2 via Chrome DevTools Protocol, evading detection.</description><pubDate>Sat, 08 Aug 2026 00:57:54 GMT</pubDate><category>Chaos Ransomware</category><category>RAT</category><category>Rust</category><category>msaRAT</category><category>Chrome DevTools Protocol</category></item><item><title>Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer</title><link>https://runtimerebel.com/blog/critical-npm-supply-chain-attack-delivers-cross-platform-rat-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-npm-supply-chain-attack-delivers-cross-platform-rat-infostealer</guid><description>Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.</description><pubDate>Sat, 08 Aug 2026 00:54:29 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>RAT</category><category>WEL1DROPPER</category></item><item><title>Compromised Joyfill npm Packages Deliver DEV#POPPER RAT</title><link>https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-joyfill-npm-packages-deliver-dev-popper-rat</guid><description>Beta versions of @joyfill/layouts and @joyfill/components npm packages compromised to deliver a DEV#POPPER RAT upon import. Node.js users at risk.</description><pubDate>Wed, 29 Jul 2026 06:32:18 GMT</pubDate><category>Joyfill</category><category>NPM</category><category>Supply Chain Attack</category><category>RAT</category><category>DEV POPPER</category><category>Node Js</category></item><item><title>Dolphin X Malware: AI-Driven Target Prioritization &amp; Defense</title><link>https://runtimerebel.com/blog/dolphin-x-malware-ai-driven-target-prioritization-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/dolphin-x-malware-ai-driven-target-prioritization-defense</guid><description>Analysis of Dolphin X, a new RAT utilizing AI to profile and rank victims, enabling threat actors to prioritize high-value targets for data exfiltration and further…</description><pubDate>Fri, 24 Jul 2026 02:46:46 GMT</pubDate><category>DolphinX</category><category>RAT</category><category>AI</category><category>Targeting</category><category>Malware Analysis</category><category>Cyber Threat</category></item><item><title>Malicious Vite npm Packages Deliver RAT via Blockchain C2</title><link>https://runtimerebel.com/blog/malicious-vite-npm-packages-deliver-rat-via-blockchain-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-vite-npm-packages-deliver-rat-via-blockchain-c2</guid><description>Seven malicious npm packages target Vite frontend projects. Dubbed ViteVenom, this software supply chain attack uses a four-tier blockchain C2 to deploy a RAT.</description><pubDate>Fri, 17 Jul 2026 20:57:56 GMT</pubDate><category>ViteVenom</category><category>ChainVeil</category><category>NPM</category><category>Vite</category><category>Software Supply Chain Attack</category><category>RAT</category><category>Blockchain C2</category></item><item><title>LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows</title><link>https://runtimerebel.com/blog/labubarat-rust-based-rat-masquerades-as-nvidia-software-on-windows</link><guid isPermaLink="true">https://runtimerebel.com/blog/labubarat-rust-based-rat-masquerades-as-nvidia-software-on-windows</guid><description>Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.</description><pubDate>Tue, 14 Jul 2026 17:20:39 GMT</pubDate><category>LabubaRAT</category><category>Rust</category><category>NVIDIA</category><category>RAT</category><category>Windows</category><category>Remote Access Trojan</category></item><item><title>MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2</title><link>https://runtimerebel.com/blog/modbeacon-rat-silver-fox-uses-grpc-for-stealthy-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/modbeacon-rat-silver-fox-uses-grpc-for-stealthy-c2</guid><description>A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.</description><pubDate>Fri, 10 Jul 2026 14:30:03 GMT</pubDate><category>MODBEACON</category><category>RAT</category><category>Silver Fox</category><category>gRPC</category><category>C2</category><category>Rust</category><category>SEO Poisoning</category></item><item><title>Malicious npm Packages Impersonate PostCSS to Deliver Windows RAT</title><link>https://runtimerebel.com/blog/malicious-npm-packages-impersonate-postcss-to-deliver-windows-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-npm-packages-impersonate-postcss-to-deliver-windows-rat</guid><description>Security researchers uncover malicious npm packages such as postcss-minify-selector-parser delivering Windows RATs via supply chain attacks. Audit your builds.</description><pubDate>Tue, 23 Jun 2026 13:10:31 GMT</pubDate><category>NPM</category><category>PostCSS</category><category>Typosquatting</category><category>RAT</category><category>JavaScript</category></item><item><title>EtherRAT Exploits GitHub Facades to Target High-Privilege Accounts</title><link>https://runtimerebel.com/blog/etherrat-exploits-github-facades-to-target-high-privilege-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/etherrat-exploits-github-facades-to-target-high-privilege-accounts</guid><description>A sophisticated campaign uses GitHub Facades and SEO poisoning to distribute EtherRAT by spoofing administrative utilities and DevOps tools.</description><pubDate>Thu, 30 Apr 2026 12:40:37 GMT</pubDate><category>EtherRAT</category><category>GitHub Facades</category><category>DevOps Security</category><category>SEO Poisoning</category><category>RAT</category></item><item><title>DPRK&apos;s &apos;Contagious Interview&apos; Spreads RATs via Dev Repositories</title><link>https://runtimerebel.com/blog/dprk-s-contagious-interview-spreads-rats-via-dev-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-s-contagious-interview-spreads-rats-via-dev-repositories</guid><description>DPRK threat actors are employing a &apos;contagious interview&apos; scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…</description><pubDate>Wed, 22 Apr 2026 20:27:05 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>Fake Job Scam</category><category>RAT</category><category>Software Supply Chain</category><category>Social Engineering</category><category>Developer Compromise</category></item><item><title>REF1695 Operation: ISO Lures Deploy RATs and Crypto Miners</title><link>https://runtimerebel.com/blog/ref1695-operation-iso-lures-deploy-rats-and-crypto-miners</link><guid isPermaLink="true">https://runtimerebel.com/blog/ref1695-operation-iso-lures-deploy-rats-and-crypto-miners</guid><description>Financially motivated REF1695 operation uses fake ISO installers to distribute RATs and crypto miners, monetizing infections via cryptojacking and CPA fraud since…</description><pubDate>Thu, 02 Apr 2026 12:26:05 GMT</pubDate><category>REF1695</category><category>Cryptocurrency Mining</category><category>RAT</category><category>ISO Files</category><category>CPA Fraud</category><category>Fake Installers</category></item><item><title>CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware</title><link>https://runtimerebel.com/blog/crystalrat-malware-a-new-maas-threat-with-rat-stealer-and-prankware</link><guid isPermaLink="true">https://runtimerebel.com/blog/crystalrat-malware-a-new-maas-threat-with-rat-stealer-and-prankware</guid><description>CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a…</description><pubDate>Thu, 02 Apr 2026 00:37:19 GMT</pubDate><category>CrystalRAT</category><category>Malware as a Service</category><category>RAT</category><category>Information Stealer</category><category>Keylogger</category><category>Prankware</category><category>Telegram</category></item><item><title>Axios Supply Chain Attack: RAT Found in Versions 1.14.1 and 0.30.4</title><link>https://runtimerebel.com/blog/axios-supply-chain-attack-rat-found-in-versions-1-14-1-and-0-30-4</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-supply-chain-attack-rat-found-in-versions-1-14-1-and-0-30-4</guid><description>Malicious Axios versions 1.14.1 and 0.30.4 inject a cross-platform RAT via a fake dependency. Identify and remediate this npm supply chain threat now.</description><pubDate>Tue, 31 Mar 2026 08:29:42 GMT</pubDate><category>Axios</category><category>NPM Security</category><category>Supply Chain Attack</category><category>RAT</category><category>Javascript Security</category><category>Malicious Dependency</category></item><item><title>GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery</title><link>https://runtimerebel.com/blog/glassworm-malware-uses-solana-dead-drops-for-stealthy-c2-delivery</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-uses-solana-dead-drops-for-stealthy-c2-delivery</guid><description>GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.</description><pubDate>Wed, 25 Mar 2026 16:31:31 GMT</pubDate><category>GlassWorm</category><category>Solana</category><category>RAT</category><category>Information Stealer</category><category>Blockchain Dead Drops</category></item><item><title>SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT</title><link>https://runtimerebel.com/blog/smartapesg-leverages-clickfix-pages-to-deploy-remcos-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/smartapesg-leverages-clickfix-pages-to-deploy-remcos-rat</guid><description>Analysis of the SmartApeSG campaign, detailing its use of deceptive &apos;ClickFix&apos; pages to distribute Remcos RAT.</description><pubDate>Sat, 14 Mar 2026 04:37:52 GMT</pubDate><category>SmartApeSG</category><category>Remcos RAT</category><category>ClickFix</category><category>RAT</category><category>Phishing</category></item><item><title>npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert</title><link>https://runtimerebel.com/blog/npm-malware-openclaw-ai-openclawai-macos-credential-theft-alert</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-malware-openclaw-ai-openclawai-macos-credential-theft-alert</guid><description>Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.</description><pubDate>Mon, 09 Mar 2026 20:11:58 GMT</pubDate><category>NPM</category><category>macOS</category><category>Malware</category><category>RAT</category><category>OpenClaw</category><category>Supply Chain Attack</category></item><item><title>Malicious Laravel Packagist Packages Deploy Cross-Platform RAT</title><link>https://runtimerebel.com/blog/malicious-laravel-packagist-packages-deploy-cross-platform-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-laravel-packagist-packages-deploy-cross-platform-rat</guid><description>Security researchers discover malicious Laravel packages on Packagist delivering cross-platform RATs to Windows, macOS, and Linux systems. Audit your PHP dependencies.</description><pubDate>Wed, 04 Mar 2026 12:17:15 GMT</pubDate><category>Packagist</category><category>Laravel</category><category>PHP</category><category>Supply Chain Attack</category><category>RAT</category><category>Nhattuanbl</category></item></channel></rss>