<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Sandworm</title><description>Cybersecurity articles tagged #Sandworm on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Leaked Russian Cyber-Ops Training Exposes Institutional Pathways</title><link>https://runtimerebel.com/blog/leaked-russian-cyber-ops-training-exposes-institutional-pathways</link><guid isPermaLink="true">https://runtimerebel.com/blog/leaked-russian-cyber-ops-training-exposes-institutional-pathways</guid><description>Leaked materials reveal Russia&apos;s institutional system for generating cyber capabilities, linking university recruitment to GRU and Sandworm units for diverse operations.</description><pubDate>Tue, 01 Sep 2026 19:02:45 GMT</pubDate><category>GRU</category><category>Sandworm</category><category>Russia</category><category>Cyber Warfare</category><category>APT28</category></item><item><title>Sandworm UAC-0145 Uses Fake Job Interviews for Arbitrary Command Execution</title><link>https://runtimerebel.com/blog/sandworm-uac-0145-uses-fake-job-interviews-for-arbitrary-command-execution</link><guid isPermaLink="true">https://runtimerebel.com/blog/sandworm-uac-0145-uses-fake-job-interviews-for-arbitrary-command-execution</guid><description>CERT-UA warns of Sandworm-linked UAC-0145 targeting IT workers with fake job interviews, deploying a modified WireGuard client that executes arbitrary commands.</description><pubDate>Sun, 16 Aug 2026 16:13:43 GMT</pubDate><category>Sandworm</category><category>UAC 0145</category><category>Social Engineering</category><category>APT44</category><category>WireGuard</category></item><item><title>Sandworm Targets IT Pros With Trojanized WireGuard VPN Client</title><link>https://runtimerebel.com/blog/sandworm-targets-it-pros-with-trojanized-wireguard-vpn-client</link><guid isPermaLink="true">https://runtimerebel.com/blog/sandworm-targets-it-pros-with-trojanized-wireguard-vpn-client</guid><description>Russian threat group Sandworm targets IT professionals using fake job interviews and trojanized WireGuard VPN clients to deliver malware.</description><pubDate>Wed, 12 Aug 2026 09:03:39 GMT</pubDate><category>Sandworm</category><category>APT44</category><category>UAC 0145</category><category>Trojan</category><category>Social Engineering</category></item><item><title>UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware</title><link>https://runtimerebel.com/blog/uac-0145-clickfix-strategy-how-sandworm-targets-ukraine-with-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uac-0145-clickfix-strategy-how-sandworm-targets-ukraine-with-malware</guid><description>Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.</description><pubDate>Sun, 19 Jul 2026 16:59:50 GMT</pubDate><category>UAC 0145</category><category>Sandworm</category><category>ClickFix</category><category>Ukraine</category><category>Malware</category><category>Phishing</category></item><item><title>Russian APTs Target Critical Infrastructure via Edge Device Exploits</title><link>https://runtimerebel.com/blog/russian-apts-target-critical-infrastructure-via-edge-device-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-apts-target-critical-infrastructure-via-edge-device-exploits</guid><description>US and allies warn of Russian state-sponsored actors targeting edge devices to infiltrate critical infrastructure. Learn how to mitigate these threats.</description><pubDate>Mon, 13 Jul 2026 11:21:02 GMT</pubDate><category>APT28</category><category>Sandworm</category><category>Cisco</category><category>Critical Infrastructure</category><category>Edge Security</category></item><item><title>Russia&apos;s Evolving Influence Ecosystem: Global Pivot &amp; AI Integration</title><link>https://runtimerebel.com/blog/russia-s-evolving-influence-ecosystem-global-pivot-ai-integration</link><guid isPermaLink="true">https://runtimerebel.com/blog/russia-s-evolving-influence-ecosystem-global-pivot-ai-integration</guid><description>Russia&apos;s influence ecosystem pivots from Ukraine-centric operations to global targets, leveraging generative AI and hybrid cyber-IO tactics.</description><pubDate>Mon, 29 Jun 2026 17:08:38 GMT</pubDate><category>Russia</category><category>Influence Operations</category><category>Information Operations</category><category>Hacktivism</category><category>Generative AI</category><category>APT44</category><category>Sandworm</category><category>NoName057 16</category><category>NATO</category><category>EU</category><category>Cyber Enabled IO</category></item><item><title>CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw</title><link>https://runtimerebel.com/blog/cve-2023-38831-russian-apts-target-ukraine-via-winrar-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-38831-russian-apts-target-ukraine-via-winrar-flaw</guid><description>Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.</description><pubDate>Tue, 09 Jun 2026 17:01:57 GMT</pubDate><category>CVE-2023-38831</category><category>WinRAR</category><category>APT28</category><category>Sandworm</category><category>Ukraine</category></item><item><title>Geopolitical Exploitation of Compromised IP Cameras</title><link>https://runtimerebel.com/blog/geopolitical-exploitation-of-compromised-ip-cameras</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-exploitation-of-compromised-ip-cameras</guid><description>Nation-states including Russia and Iran are weaponizing compromised IP cameras for battlefield intelligence and critical infrastructure surveillance.</description><pubDate>Fri, 27 Mar 2026 16:26:24 GMT</pubDate><category>Iot Security</category><category>IP Cameras</category><category>Sandworm</category><category>Geopolitical Cyber Risk</category><category>Surveillance</category></item></channel></rss>