<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #State Sponsored</title><description>Cybersecurity articles tagged #State Sponsored on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>PurpleDelta: North Korean IT Workers Exploit Remote Hiring</title><link>https://runtimerebel.com/blog/purpledelta-north-korean-it-workers-exploit-remote-hiring</link><guid isPermaLink="true">https://runtimerebel.com/blog/purpledelta-north-korean-it-workers-exploit-remote-hiring</guid><description>Recorded Future exposes PurpleDelta, North Korean IT workers using sophisticated fraudulent employment, AI, and extensive vetting evasion to fund DPRK military programs.</description><pubDate>Tue, 18 Aug 2026 16:25:57 GMT</pubDate><category>North Korea</category><category>State Sponsored</category><category>Supply Chain Risk</category><category>PurpleDelta</category><category>Fraudulent Employment</category></item><item><title>Microsoft OWA Exploit: Russian Hackers Bypass Credential Rotations</title><link>https://runtimerebel.com/blog/microsoft-owa-exploit-russian-hackers-bypass-credential-rotations</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-owa-exploit-russian-hackers-bypass-credential-rotations</guid><description>Russian threat actors exploit a Microsoft Outlook Web Access (OWA) flaw to maintain persistent mailbox access even after passwords are changed or rotated.</description><pubDate>Thu, 30 Jul 2026 10:25:52 GMT</pubDate><category>APT28</category><category>Microsoft OWA</category><category>Credential Rotation Bypass</category><category>State Sponsored</category></item><item><title>Zimbra Zero-Day Exploited by Laundry Bear Against US &amp; Ukraine</title><link>https://runtimerebel.com/blog/zimbra-zero-day-exploited-by-laundry-bear-against-us-ukraine</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-zero-day-exploited-by-laundry-bear-against-us-ukraine</guid><description>Russian state-sponsored group &apos;Laundry Bear&apos; exploits a Zimbra zero-day via &apos;half-click&apos; phishing, targeting US and Ukrainian entities for credential theft and backdoor…</description><pubDate>Fri, 24 Jul 2026 02:47:14 GMT</pubDate><category>Laundry Bear</category><category>Zimbra</category><category>Zero-Day</category><category>Phishing</category><category>US</category><category>Ukraine</category><category>State Sponsored</category></item><item><title>Iran-Linked Hackers Deploy New Cavern C2 Against Israeli Targets</title><link>https://runtimerebel.com/blog/iran-linked-hackers-deploy-new-cavern-c2-against-israeli-targets</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-linked-hackers-deploy-new-cavern-c2-against-israeli-targets</guid><description>Iranian state-sponsored threat actors are using a novel modular C2 framework, Cavern (Cav3rn), to compromise Israeli IT and government entities.</description><pubDate>Mon, 06 Jul 2026 21:38:48 GMT</pubDate><category>Cavern</category><category>Cav3rn</category><category>Iran</category><category>MOIS</category><category>Israeli Organizations</category><category>State Sponsored</category><category>Threat Cluster</category></item><item><title>China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor</title><link>https://runtimerebel.com/blog/china-linked-apt-targets-southeast-asia-critical-systems-with-new-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-linked-apt-targets-southeast-asia-critical-systems-with-new-backdoor</guid><description>A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.</description><pubDate>Wed, 01 Jul 2026 05:41:17 GMT</pubDate><category>China Linked APT</category><category>Southeast Asia</category><category>Critical Infrastructure</category><category>Backdoor</category><category>State Sponsored</category><category>Espionage</category><category>Cyber Warfare</category></item><item><title>US Targets Russian-Linked UNC5792, UNC4221 Hackers of Messaging Apps</title><link>https://runtimerebel.com/blog/us-targets-russian-linked-unc5792-unc4221-hackers-of-messaging-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-targets-russian-linked-unc5792-unc4221-hackers-of-messaging-apps</guid><description>US State Dept. offers $10M for info on Russian-linked UNC5792 &amp; UNC4221 groups targeting WhatsApp, Signal users. Learn about nation-state threats.</description><pubDate>Mon, 29 Jun 2026 17:06:46 GMT</pubDate><category>UNC5792</category><category>UNC4221</category><category>Russia</category><category>State Sponsored</category><category>WhatsApp</category><category>Signal</category><category>Targeting</category></item><item><title>JDY Botnet Expansion: China-Linked Reconnaissance on SOHO/IoT Devices</title><link>https://runtimerebel.com/blog/jdy-botnet-expansion-china-linked-reconnaissance-on-soho-iot-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/jdy-botnet-expansion-china-linked-reconnaissance-on-soho-iot-devices</guid><description>China-linked JDY botnet now controls 1,500+ SOHO/IoT devices, actively expanding cyber reconnaissance for state-sponsored operations.</description><pubDate>Wed, 10 Jun 2026 17:13:48 GMT</pubDate><category>JDY</category><category>Botnet</category><category>China</category><category>SOHO</category><category>IoT</category><category>Cyber Reconnaissance</category><category>State Sponsored</category><category>Threat Intelligence</category></item><item><title>UAE Critical Infrastructure Faces Surge in Geopolitical Cyberattacks</title><link>https://runtimerebel.com/blog/uae-critical-infrastructure-faces-surge-in-geopolitical-cyberattacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/uae-critical-infrastructure-faces-surge-in-geopolitical-cyberattacks</guid><description>Breach attempts against the UAE have tripled following regional tensions, specifically targeting critical infrastructure and government sectors.</description><pubDate>Wed, 06 May 2026 12:49:45 GMT</pubDate><category>UAE</category><category>Middle East</category><category>Critical Infrastructure</category><category>State Sponsored</category><category>Geopolitical Conflict</category></item><item><title>DarkSword: Analyzing the GTIG iOS Full-Chain Zero-Day Exploit</title><link>https://runtimerebel.com/blog/darksword-analyzing-the-gtig-ios-full-chain-zero-day-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/darksword-analyzing-the-gtig-ios-full-chain-zero-day-exploit</guid><description>Google Threat Intelligence Group uncovers DarkSword, a sophisticated iOS exploit chain leveraging multiple zero-days for state-sponsored surveillance.</description><pubDate>Tue, 05 May 2026 12:39:04 GMT</pubDate><category>DarkSword</category><category>iOS</category><category>GTIG</category><category>Spyware</category><category>State Sponsored</category></item><item><title>Fast16 Malware: Analyzing the Precursor to Stuxnet Sabotage</title><link>https://runtimerebel.com/blog/fast16-malware-analyzing-the-precursor-to-stuxnet-sabotage</link><guid isPermaLink="true">https://runtimerebel.com/blog/fast16-malware-analyzing-the-precursor-to-stuxnet-sabotage</guid><description>Analysis of the Fast16 malware, a state-sponsored tool designed to sabotage high-precision mathematical simulations and physical computation processes.</description><pubDate>Thu, 30 Apr 2026 12:42:39 GMT</pubDate><category>Fast16</category><category>Stuxnet</category><category>Ics Sabotage</category><category>State Sponsored</category><category>Iran</category></item><item><title>Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack</title><link>https://runtimerebel.com/blog/grinex-exchange-shuts-down-after-13-74m-state-sponsored-hack</link><guid isPermaLink="true">https://runtimerebel.com/blog/grinex-exchange-shuts-down-after-13-74m-state-sponsored-hack</guid><description>Sanctioned exchange Grinex halts operations following a $13.74M hack attributed to Western intelligence agencies. Analysis of TTPs and geopolitical impact.</description><pubDate>Sat, 18 Apr 2026 12:18:02 GMT</pubDate><category>Grinex</category><category>Cryptocurrency</category><category>State Sponsored</category><category>Sanctions</category><category>Financial Cybercrime</category></item><item><title>Apple DarkSword Protection Expands: Mitigating CVE-2023-38604 Zero-Click Exploits</title><link>https://runtimerebel.com/blog/apple-darksword-protection-expands-mitigating-cve-2023-38604-zero-click-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-darksword-protection-expands-mitigating-cve-2023-38604-zero-click-exploits</guid><description>Apple expands DarkSword exploit protection to all users, enhancing defenses against state-sponsored and commercial zero-click attacks like CVE-2023-38604.</description><pubDate>Thu, 02 Apr 2026 16:27:21 GMT</pubDate><category>Apple</category><category>DarkSword</category><category>CVE-2023-38604</category><category>Zero Click</category><category>Exploit Kit</category><category>State Sponsored</category><category>Commercial Spyware</category><category>iOS</category><category>macOS</category><category>iPadOS</category><category>watchOS</category><category>tvOS</category></item><item><title>Coruna: Sophisticated iPhone Hacking Toolkit Bypasses iOS Defenses</title><link>https://runtimerebel.com/blog/coruna-sophisticated-iphone-hacking-toolkit-bypasses-ios-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/coruna-sophisticated-iphone-hacking-toolkit-bypasses-ios-defenses</guid><description>Google researchers uncovered &quot;Coruna,&quot; a powerful iOS exploit kit leveraging 23 vulnerabilities to silently install malware on iPhones, likely state-sponsored.</description><pubDate>Thu, 02 Apr 2026 12:30:01 GMT</pubDate><category>Coruna</category><category>iOS</category><category>iPhone</category><category>Exploit Kit</category><category>State Sponsored</category><category>Mobile Security</category></item><item><title>Star Blizzard (APT28) Adopts DarkSword iOS Exploit Kit</title><link>https://runtimerebel.com/blog/star-blizzard-apt28-adopts-darksword-ios-exploit-kit</link><guid isPermaLink="true">https://runtimerebel.com/blog/star-blizzard-apt28-adopts-darksword-ios-exploit-kit</guid><description>Russian APT Star Blizzard (APT28) now uses the DarkSword iOS exploit kit to target government, finance, and academia, increasing mobile threat exposure.</description><pubDate>Mon, 30 Mar 2026 12:35:23 GMT</pubDate><category>Star Blizzard</category><category>APT28</category><category>Fancy Bear</category><category>Nobelium</category><category>DarkSword</category><category>iOS</category><category>Exploit Kit</category><category>State Sponsored</category><category>Mobile Security</category><category>Spear Phishing</category></item><item><title>Iranian Hackers Target Kash Patel: US Offers $10M Bounty</title><link>https://runtimerebel.com/blog/iranian-hackers-target-kash-patel-us-offers-10m-bounty</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-hackers-target-kash-patel-us-offers-10m-bounty</guid><description>The FBI confirms Iranian state-sponsored hackers compromised Kash Patel’s personal email, leading the U.S. to offer a $10M reward for information.</description><pubDate>Mon, 30 Mar 2026 08:42:33 GMT</pubDate><category>Iran</category><category>FBI</category><category>Kash Patel</category><category>Election Interference</category><category>State Sponsored</category><category>APT</category></item><item><title>Iranian Cyber Infrastructure Hardening Ahead of Operation Epic Fury</title><link>https://runtimerebel.com/blog/iranian-cyber-infrastructure-hardening-ahead-of-operation-epic-fury</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-cyber-infrastructure-hardening-ahead-of-operation-epic-fury</guid><description>Analysis of Iran&apos;s six-month buildup of US-based shell companies and resilient cyber infrastructure to survive kinetic strikes and maintain hacking operations.</description><pubDate>Thu, 19 Mar 2026 16:25:33 GMT</pubDate><category>Iran</category><category>Emennet Pasargad</category><category>Epic Fury</category><category>Infrastructure Hardening</category><category>State Sponsored</category></item><item><title>Google Disrupts Chinese Espionage Actor UNC2814 Targeting Telecoms</title><link>https://runtimerebel.com/blog/google-disrupts-chinese-espionage-actor-unc2814-targeting-telecoms</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-disrupts-chinese-espionage-actor-unc2814-targeting-telecoms</guid><description>Google and Mandiant disrupt UNC2814, a Chinese state-sponsored actor active since 2017, targeting 42 countries across telecom and government sectors.</description><pubDate>Wed, 25 Feb 2026 16:34:10 GMT</pubDate><category>UNC2814</category><category>China</category><category>Cyber Espionage</category><category>Google TAG</category><category>Mandiant</category><category>Telecommunications</category><category>State Sponsored</category></item></channel></rss>