<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Russia</title><description>Cybersecurity articles tagged #Russia on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Leaked Russian Cyber-Ops Training Exposes Institutional Pathways</title><link>https://runtimerebel.com/blog/leaked-russian-cyber-ops-training-exposes-institutional-pathways</link><guid isPermaLink="true">https://runtimerebel.com/blog/leaked-russian-cyber-ops-training-exposes-institutional-pathways</guid><description>Leaked materials reveal Russia&apos;s institutional system for generating cyber capabilities, linking university recruitment to GRU and Sandworm units for diverse operations.</description><pubDate>Tue, 01 Sep 2026 19:02:45 GMT</pubDate><category>GRU</category><category>Sandworm</category><category>Russia</category><category>Cyber Warfare</category><category>APT28</category></item><item><title>BusySnake Infostealer Targets Critical Infrastructure: Armored Likho&apos;s TTPs</title><link>https://runtimerebel.com/blog/busysnake-infostealer-targets-critical-infrastructure-armored-likho-s-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/busysnake-infostealer-targets-critical-infrastructure-armored-likho-s-ttps</guid><description>BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.</description><pubDate>Tue, 07 Jul 2026 03:34:06 GMT</pubDate><category>BusySnake</category><category>Infostealer</category><category>Armored Likho</category><category>Critical Infrastructure</category><category>Government</category><category>Electrical Power</category><category>Russia</category><category>Brazil</category><category>Kazakhstan</category></item><item><title>Russia&apos;s Evolving Influence Ecosystem: Global Pivot &amp; AI Integration</title><link>https://runtimerebel.com/blog/russia-s-evolving-influence-ecosystem-global-pivot-ai-integration</link><guid isPermaLink="true">https://runtimerebel.com/blog/russia-s-evolving-influence-ecosystem-global-pivot-ai-integration</guid><description>Russia&apos;s influence ecosystem pivots from Ukraine-centric operations to global targets, leveraging generative AI and hybrid cyber-IO tactics.</description><pubDate>Mon, 29 Jun 2026 17:08:38 GMT</pubDate><category>Russia</category><category>Influence Operations</category><category>Information Operations</category><category>Hacktivism</category><category>Generative AI</category><category>APT44</category><category>Sandworm</category><category>NoName057 16</category><category>NATO</category><category>EU</category><category>Cyber Enabled IO</category></item><item><title>US Targets Russian-Linked UNC5792, UNC4221 Hackers of Messaging Apps</title><link>https://runtimerebel.com/blog/us-targets-russian-linked-unc5792-unc4221-hackers-of-messaging-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-targets-russian-linked-unc5792-unc4221-hackers-of-messaging-apps</guid><description>US State Dept. offers $10M for info on Russian-linked UNC5792 &amp; UNC4221 groups targeting WhatsApp, Signal users. Learn about nation-state threats.</description><pubDate>Mon, 29 Jun 2026 17:06:46 GMT</pubDate><category>UNC5792</category><category>UNC4221</category><category>Russia</category><category>State Sponsored</category><category>WhatsApp</category><category>Signal</category><category>Targeting</category></item><item><title>Iranian &amp; Russian Cyber-Enabled Maritime Sanctions Evasion Tactics</title><link>https://runtimerebel.com/blog/iranian-russian-cyber-enabled-maritime-sanctions-evasion-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-russian-cyber-enabled-maritime-sanctions-evasion-tactics</guid><description>Explore the sophisticated cyber tactics used by Iranian and Russian shadow fleets to evade sanctions, leveraging fake maritime websites and fraudulent documents.</description><pubDate>Fri, 12 Jun 2026 09:43:20 GMT</pubDate><category>Iran</category><category>Russia</category><category>Sanctions Evasion</category><category>Maritime Security</category><category>Shadow Fleet</category><category>Fraud</category><category>Digital Identity</category><category>Illicit Shipping</category></item><item><title>THE.Hosting: Dutch Raid Fails to Halt Russian Bulletproof Ops</title><link>https://runtimerebel.com/blog/the-hosting-dutch-raid-fails-to-halt-russian-bulletproof-ops</link><guid isPermaLink="true">https://runtimerebel.com/blog/the-hosting-dutch-raid-fails-to-halt-russian-bulletproof-ops</guid><description>Dutch law enforcement seized 800 servers and arrested two operators of THE.Hosting, a Russian bulletproof host, but its core IP infrastructure persists.</description><pubDate>Thu, 28 May 2026 20:54:11 GMT</pubDate><category>THE Hosting</category><category>Bulletproof Hosting</category><category>Cybercrime Infrastructure</category><category>Law Enforcement Operation</category><category>Russia</category><category>Netherlands</category></item><item><title>GCHQ Warning: Russian Gray Zone Tactics and AI-Driven Cyber Threats</title><link>https://runtimerebel.com/blog/gchq-warning-russian-gray-zone-tactics-and-ai-driven-cyber-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/gchq-warning-russian-gray-zone-tactics-and-ai-driven-cyber-threats</guid><description>GCHQ Director Anne Keast-Butler warns that AI is an unstoppable force that Russian state-sponsored actors are leveraging for gray zone cyber operations.</description><pubDate>Wed, 27 May 2026 20:48:14 GMT</pubDate><category>GCHQ</category><category>Russia</category><category>Artificial Intelligence</category><category>Gray Zone</category><category>Nation State</category></item><item><title>Silver Fox APT: Tax-Themed Phishing Delivers ABCDoor to India, Russia</title><link>https://runtimerebel.com/blog/silver-fox-apt-tax-themed-phishing-delivers-abcdoor-to-india-russia</link><guid isPermaLink="true">https://runtimerebel.com/blog/silver-fox-apt-tax-themed-phishing-delivers-abcdoor-to-india-russia</guid><description>China-backed Silver Fox APT targets organizations in India and Russia with over 1,600 tax-themed phishing messages to deploy ABCDoor backdoor and ValleyRAT.</description><pubDate>Mon, 04 May 2026 16:46:54 GMT</pubDate><category>Silver Fox</category><category>ABCSDoor</category><category>ValleyRAT</category><category>Phishing</category><category>India</category><category>Russia</category><category>APT</category><category>Backdoor</category><category>Tax Themed Attacks</category></item><item><title>Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing</title><link>https://runtimerebel.com/blog/silver-fox-deploys-abcdoor-malware-via-tax-themed-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/silver-fox-deploys-abcdoor-malware-via-tax-themed-phishing</guid><description>China-linked threat actor Silver Fox targets Russian and Indian organizations using tax-themed lures to deliver the novel ABCDoor malware via phishing waves.</description><pubDate>Mon, 04 May 2026 12:42:24 GMT</pubDate><category>Silver Fox</category><category>ABCDoor</category><category>Phishing</category><category>India</category><category>Russia</category><category>China Linked</category></item><item><title>US Strategic Pivot: Cyber Risk and Geopolitical Shift Analysis</title><link>https://runtimerebel.com/blog/us-strategic-pivot-cyber-risk-and-geopolitical-shift-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-strategic-pivot-cyber-risk-and-geopolitical-shift-analysis</guid><description>Analysis of the US strategic shift toward force-driven security and its implications for cyber threats from China, Russia, Iran, and criminal groups.</description><pubDate>Thu, 30 Apr 2026 16:41:48 GMT</pubDate><category>Geopolitics</category><category>China</category><category>Russia</category><category>Iran</category><category>Transnational Organized Crime</category><category>Western Hemisphere</category></item><item><title>UK Cyber Chief: Russia, Iran, China Drive Top Cyber Threats</title><link>https://runtimerebel.com/blog/uk-cyber-chief-russia-iran-china-drive-top-cyber-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-cyber-chief-russia-iran-china-drive-top-cyber-threats</guid><description>NCSC warns British businesses of escalating cyber threats from state-sponsored groups in Russia, Iran, and China, urging preparedness for potential large-scale attacks.</description><pubDate>Wed, 22 Apr 2026 20:26:36 GMT</pubDate><category>UK</category><category>NCSC</category><category>Russia</category><category>Iran</category><category>China</category><category>Nation State</category><category>Cyber Warfare</category><category>Critical Infrastructure</category></item><item><title>APT28 Analysis: Mitigation Strategies Against Fancy Bear Campaigns</title><link>https://runtimerebel.com/blog/apt28-analysis-mitigation-strategies-against-fancy-bear-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-analysis-mitigation-strategies-against-fancy-bear-campaigns</guid><description>A technical analysis of APT28&apos;s global operations, highlighting the necessity of Zero Trust and rapid patching to counter Fancy Bear threat activity.</description><pubDate>Fri, 10 Apr 2026 08:40:01 GMT</pubDate><category>APT28</category><category>Fancy Bear</category><category>Russia</category><category>Nation State</category><category>Zero Trust</category></item><item><title>Russian Hackers Exploit Routers to Steal Microsoft Office Tokens</title><link>https://runtimerebel.com/blog/russian-hackers-exploit-routers-to-steal-microsoft-office-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-hackers-exploit-routers-to-steal-microsoft-office-tokens</guid><description>Russian military intelligence-linked hackers exploited known router flaws to harvest Microsoft Office authentication tokens from over 18,000 networks, posing a…</description><pubDate>Tue, 07 Apr 2026 20:19:57 GMT</pubDate><category>Russia</category><category>Military Intelligence</category><category>Router Security</category><category>Microsoft Office</category><category>Authentication Tokens</category><category>Nation State</category><category>Espionage</category></item><item><title>Russian Authorities Arrest LeakBase Admin for Stolen Data Sales</title><link>https://runtimerebel.com/blog/russian-authorities-arrest-leakbase-admin-for-stolen-data-sales</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-authorities-arrest-leakbase-admin-for-stolen-data-sales</guid><description>Russian law enforcement arrested the alleged administrator of LeakBase, a major marketplace for stolen credentials, disrupting a key cybercrime resource.</description><pubDate>Wed, 25 Mar 2026 20:16:40 GMT</pubDate><category>LeakBase</category><category>Cybercrime</category><category>Stolen Credentials</category><category>Russia</category><category>Law Enforcement</category></item><item><title>Sednit/APT28 Resurfaces: Advanced Toolkit Threat Analysis</title><link>https://runtimerebel.com/blog/sednit-apt28-resurfaces-advanced-toolkit-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/sednit-apt28-resurfaces-advanced-toolkit-threat-analysis</guid><description>Russian-affiliated APT Sednit (APT28) has returned with sophisticated new malware, shifting from simple implants. Understand their updated TTPs and mitigation strategies.</description><pubDate>Tue, 10 Mar 2026 20:14:43 GMT</pubDate><category>Sednit</category><category>APT28</category><category>Russia</category><category>Nation State</category><category>Malware</category><category>Toolkit</category></item><item><title>Ex-L3Harris Executive Sentenced for Selling Zero-Days to Russia</title><link>https://runtimerebel.com/blog/ex-l3harris-executive-sentenced-for-selling-zero-days-to-russia</link><guid isPermaLink="true">https://runtimerebel.com/blog/ex-l3harris-executive-sentenced-for-selling-zero-days-to-russia</guid><description>Former Trenchant CEO James Michael Robinson sentenced to 90 months for stealing zero-day exploits and selling them to a Russian state-linked broker.</description><pubDate>Wed, 25 Feb 2026 12:25:01 GMT</pubDate><category>L3Harris</category><category>Trenchant</category><category>Zero-Day</category><category>Insider Threat</category><category>Russia</category><category>Espionage</category><category>Cyber Exploits</category></item><item><title>US Treasury Sanctions Russian Broker for Stolen Zero-Day Exploits</title><link>https://runtimerebel.com/blog/us-treasury-sanctions-russian-broker-for-stolen-zero-day-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-treasury-sanctions-russian-broker-for-stolen-zero-day-exploits</guid><description>The US sanctions Artem Kruglov and associated firms for brokering stolen hacking tools and zero-day exploits for Russian intelligence services.</description><pubDate>Wed, 25 Feb 2026 12:24:10 GMT</pubDate><category>OFAC</category><category>Sanctions</category><category>Zero-Day</category><category>Artem Kruglov</category><category>Russia</category><category>Cyber Espionage</category><category>SVR</category></item><item><title>Russia&apos;s Escalating New Generation Hybrid Warfare in Europe</title><link>https://runtimerebel.com/blog/russia-s-escalating-new-generation-hybrid-warfare-in-europe</link><guid isPermaLink="true">https://runtimerebel.com/blog/russia-s-escalating-new-generation-hybrid-warfare-in-europe</guid><description>Analysis of Russia&apos;s coordinated New Generation Warfare against NATO, blending cyber attacks, sabotage, and influence operations. Understand the threat.</description><pubDate>Wed, 25 Feb 2026 04:48:06 GMT</pubDate><category>Russia</category><category>New Generation Warfare</category><category>Hybrid Warfare</category><category>NATO</category><category>Cyberattacks</category><category>Sabotage</category><category>Influence Operations</category><category>Geopolitical Threat</category></item><item><title>APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe</title><link>https://runtimerebel.com/blog/apt28-operation-macromaze-webhook-driven-macro-execution-targeting-western-europe</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-operation-macromaze-webhook-driven-macro-execution-targeting-western-europe</guid><description>Analysis of a targeted campaign attributed to APT28, utilizing macro-enabled documents and legitimate webhook services for command-and-control obfuscation.</description><pubDate>Tue, 24 Feb 2026 04:40:50 GMT</pubDate><category>APT28</category><category>MacroMaze</category><category>Webhooks</category><category>Russia</category><category>Espionage</category></item></channel></rss>