<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Spear Phishing</title><description>Cybersecurity articles tagged #Spear Phishing on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>APT28&apos;s HOOKEDGE Backdoor Targets European Diplomacy</title><link>https://runtimerebel.com/blog/apt28-s-hookedge-backdoor-targets-european-diplomacy</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-s-hookedge-backdoor-targets-european-diplomacy</guid><description>Russian state-sponsored BlueDelta (APT28) leverages HOOKEDGE backdoor via macro-enabled documents to target European government and diplomatic entities.</description><pubDate>Tue, 01 Sep 2026 02:51:27 GMT</pubDate><category>Spear Phishing</category><category>BlueDelta</category><category>APT28</category><category>HOOKEDGE</category><category>HEADLACE</category></item><item><title>Detecting AI-Driven Polymorphic Phishing Attacks</title><link>https://runtimerebel.com/blog/detecting-ai-driven-polymorphic-phishing-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-ai-driven-polymorphic-phishing-attacks</guid><description>AI-powered phishing attacks leverage personalization and polymorphic evasion, challenging traditional filters. MSPs must focus on post-compromise detection.</description><pubDate>Fri, 21 Aug 2026 08:29:38 GMT</pubDate><category>Spear Phishing</category><category>Email Security</category><category>Threat Detection</category><category>AI Powered Phishing</category><category>Polymorphic Phishing</category></item><item><title>NSO Group&apos;s WhatsApp Phishing Blocked: Meta Files Contempt Order</title><link>https://runtimerebel.com/blog/nso-group-s-whatsapp-phishing-blocked-meta-files-contempt-order</link><guid isPermaLink="true">https://runtimerebel.com/blog/nso-group-s-whatsapp-phishing-blocked-meta-files-contempt-order</guid><description>Meta detected and blocked new spear-phishing attacks by NSO Group targeting WhatsApp users, leading to a federal court contempt order filing.</description><pubDate>Mon, 08 Jun 2026 20:57:34 GMT</pubDate><category>NSO Group</category><category>WhatsApp</category><category>Phishing</category><category>Spear Phishing</category><category>Spyware Vendor</category><category>Meta</category></item><item><title>China&apos;s Dual-Method Cyberattack Targets Czech, Taiwan Orgs with Azureveil</title><link>https://runtimerebel.com/blog/china-s-dual-method-cyberattack-targets-czech-taiwan-orgs-with-azureveil</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-s-dual-method-cyberattack-targets-czech-taiwan-orgs-with-azureveil</guid><description>Nation-state actors linked to China employ dual-method spear-phishing with Azureveil malware to target Czech and Taiwan organizations for data theft.</description><pubDate>Tue, 02 Jun 2026 21:12:29 GMT</pubDate><category>China</category><category>Azureveil</category><category>Spear Phishing</category><category>Data Theft</category><category>Czech Republic</category><category>Taiwan</category><category>Nation State</category></item><item><title>Operation Dragon Weave: APT Targeting Czech Republic and Taiwan</title><link>https://runtimerebel.com/blog/operation-dragon-weave-apt-targeting-czech-republic-and-taiwan</link><guid isPermaLink="true">https://runtimerebel.com/blog/operation-dragon-weave-apt-targeting-czech-republic-and-taiwan</guid><description>China-aligned Operation Dragon Weave targets Czech and Taiwanese government and tech sectors using spear-phishing to deploy the AdaptixC2 agent framework.</description><pubDate>Mon, 01 Jun 2026 14:10:57 GMT</pubDate><category>Operation Dragon Weave</category><category>AdaptixC2</category><category>China Aligned</category><category>Spear Phishing</category><category>Czech Republic</category><category>Taiwan</category></item><item><title>FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing</title><link>https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</guid><description>Belarussian APT &apos;FrostyNeighbor&apos; is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…</description><pubDate>Thu, 14 May 2026 20:38:13 GMT</pubDate><category>FrostyNeighbor</category><category>APT</category><category>Belarus</category><category>Poland</category><category>Ukraine</category><category>Espionage</category><category>Spear Phishing</category><category>Government</category><category>Nation State</category></item><item><title>Chinese Spear-Phishing Campaign Targets NASA Defense Software</title><link>https://runtimerebel.com/blog/chinese-spear-phishing-campaign-targets-nasa-defense-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-spear-phishing-campaign-targets-nasa-defense-software</guid><description>NASA OIG reveals a multi-year spear-phishing campaign by a Chinese national impersonating researchers to exfiltrate sensitive U.S. defense software.</description><pubDate>Fri, 24 Apr 2026 16:25:59 GMT</pubDate><category>NASA</category><category>China</category><category>Spear Phishing</category><category>Export Control</category><category>Defense Software</category><category>OIG Report</category></item><item><title>UAT-10362 Targets Taiwanese NGOs with LucidRook Malware</title><link>https://runtimerebel.com/blog/uat-10362-targets-taiwanese-ngos-with-lucidrook-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-10362-targets-taiwanese-ngos-with-lucidrook-malware</guid><description>Runtime Rebel analyzes UAT-10362&apos;s sophisticated spear-phishing campaigns deploying new Lua-based LucidRook malware against Taiwanese NGOs and universities.</description><pubDate>Fri, 10 Apr 2026 00:40:34 GMT</pubDate><category>UAT 10362</category><category>LucidRook</category><category>Taiwan</category><category>NGO</category><category>Spear Phishing</category><category>Lua Malware</category><category>Rust Malware</category><category>APT</category></item><item><title>Star Blizzard (APT28) Adopts DarkSword iOS Exploit Kit</title><link>https://runtimerebel.com/blog/star-blizzard-apt28-adopts-darksword-ios-exploit-kit</link><guid isPermaLink="true">https://runtimerebel.com/blog/star-blizzard-apt28-adopts-darksword-ios-exploit-kit</guid><description>Russian APT Star Blizzard (APT28) now uses the DarkSword iOS exploit kit to target government, finance, and academia, increasing mobile threat exposure.</description><pubDate>Mon, 30 Mar 2026 12:35:23 GMT</pubDate><category>Star Blizzard</category><category>APT28</category><category>Fancy Bear</category><category>Nobelium</category><category>DarkSword</category><category>iOS</category><category>Exploit Kit</category><category>State Sponsored</category><category>Mobile Security</category><category>Spear Phishing</category></item><item><title>Iranian-Linked Handala Group Breaches Kash Patel&apos;s Personal Email</title><link>https://runtimerebel.com/blog/iranian-linked-handala-group-breaches-kash-patel-s-personal-email</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-linked-handala-group-breaches-kash-patel-s-personal-email</guid><description>FBI confirms Iranian-linked Handala hackers breached Director nominee Kash Patel&apos;s personal email, leaking documents and highlighting spear-phishing risks.</description><pubDate>Mon, 30 Mar 2026 00:41:00 GMT</pubDate><category>Handala</category><category>Iran</category><category>Kash Patel</category><category>FBI</category><category>Spear Phishing</category><category>Espionage</category></item><item><title>TA446 Deploys Leaked DarkSword iOS Exploit Kit — Technical Analysis</title><link>https://runtimerebel.com/blog/ta446-deploys-leaked-darksword-ios-exploit-kit-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/ta446-deploys-leaked-darksword-ios-exploit-kit-technical-analysis</guid><description>Russian threat actor TA446 (Callisto) is targeting iOS users with the leaked DarkSword exploit kit. Learn how to detect and defend against this campaign.</description><pubDate>Sat, 28 Mar 2026 08:18:53 GMT</pubDate><category>TA446</category><category>Callisto</category><category>DarkSword</category><category>iOS Exploitation</category><category>Spear Phishing</category></item><item><title>SideWinder APT Expands Southeast Asia Espionage Campaign</title><link>https://runtimerebel.com/blog/sidewinder-apt-expands-southeast-asia-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/sidewinder-apt-expands-southeast-asia-espionage-campaign</guid><description>SideWinder APT targets government and telecom sectors in Southeast Asia using spear-phishing and rotating infrastructure for persistent espionage operations.</description><pubDate>Wed, 18 Mar 2026 16:31:14 GMT</pubDate><category>SideWinder</category><category>APT</category><category>Southeast Asia</category><category>Spear Phishing</category><category>CVE-2017-11882</category></item><item><title>Konni Group Deploys EndRAT via Phishing and KakaoTalk Hijacking</title><link>https://runtimerebel.com/blog/konni-group-deploys-endrat-via-phishing-and-kakaotalk-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/konni-group-deploys-endrat-via-phishing-and-kakaotalk-hijacking</guid><description>North Korean threat actor Konni leverages spear-phishing and KakaoTalk desktop exploitation to distribute EndRAT malware and facilitate lateral movement.</description><pubDate>Tue, 17 Mar 2026 12:30:14 GMT</pubDate><category>Konni</category><category>Endrat</category><category>Kakaotalk</category><category>APT</category><category>Spear Phishing</category></item><item><title>MuddyWater Deploys BugSleep Backdoor in Targeted Regional Campaigns</title><link>https://runtimerebel.com/blog/muddywater-deploys-bugsleep-backdoor-in-targeted-regional-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/muddywater-deploys-bugsleep-backdoor-in-targeted-regional-campaigns</guid><description>Iranian state actor MuddyWater introduces the custom BugSleep backdoor, targeting Middle Eastern and African entities using spear-phishing and RMM abuse.</description><pubDate>Tue, 24 Feb 2026 08:22:38 GMT</pubDate><category>MuddyWater</category><category>BugSleep</category><category>MOIS</category><category>Spear Phishing</category><category>RMM Abuse</category><category>Iran</category><category>Cyber Espionage</category></item></channel></rss>