<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Steganography</title><description>Cybersecurity articles tagged #Steganography on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>DOUBLECUP Malware: Appended PowerShell Payloads in PNG Files</title><link>https://runtimerebel.com/blog/doublecup-malware-appended-powershell-payloads-in-png-files</link><guid isPermaLink="true">https://runtimerebel.com/blog/doublecup-malware-appended-powershell-payloads-in-png-files</guid><description>Analysis of DOUBLECUP malware reveals a deceptive technique: appending cleartext PowerShell payloads to PNG image files, bypassing traditional steganography.</description><pubDate>Mon, 24 Aug 2026 08:39:29 GMT</pubDate><category>Malware</category><category>PowerShell</category><category>Steganography</category><category>Threat Intelligence</category><category>DOUBLECUP</category></item><item><title>North Korean Actors Use SVG Steganography to Deliver OtterCookie</title><link>https://runtimerebel.com/blog/north-korean-actors-use-svg-steganography-to-deliver-ottercookie</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-actors-use-svg-steganography-to-deliver-ottercookie</guid><description>North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.</description><pubDate>Fri, 17 Jul 2026 17:13:52 GMT</pubDate><category>Lazarus Group</category><category>OtterCookie</category><category>Contagious Interview</category><category>Steganography</category><category>Node Js</category><category>Infostealer</category></item><item><title>Ghostcommit: Hidden Prompt Injection in Images Targets AI Agents</title><link>https://runtimerebel.com/blog/ghostcommit-hidden-prompt-injection-in-images-targets-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghostcommit-hidden-prompt-injection-in-images-targets-ai-agents</guid><description>Researchers demonstrate Ghostcommit, a technique using images to hide prompt injection attacks that trick AI agents into exfiltrating repository secrets.</description><pubDate>Sat, 11 Jul 2026 09:39:43 GMT</pubDate><category>Ghostcommit</category><category>Prompt Injection</category><category>Steganography</category><category>AI Security</category><category>Coderabbit</category><category>Bugbot</category></item><item><title>Microsoft Pulls 119 Malicious StegoAd Edge Extensions</title><link>https://runtimerebel.com/blog/microsoft-pulls-119-malicious-stegoad-edge-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-pulls-119-malicious-stegoad-edge-extensions</guid><description>Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.</description><pubDate>Mon, 29 Jun 2026 09:51:08 GMT</pubDate><category>Microsoft Edge</category><category>StegoAd</category><category>Browser Security</category><category>Steganography</category><category>Adware</category></item><item><title>MSI-Branded Image Steganography: Analysis of WeTransfer Phishing</title><link>https://runtimerebel.com/blog/msi-branded-image-steganography-analysis-of-wetransfer-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/msi-branded-image-steganography-analysis-of-wetransfer-phishing</guid><description>Analysis of a recurring phishing campaign using steganography in MSI-branded images to deliver malicious payloads via WeTransfer links and bypass security.</description><pubDate>Fri, 05 Jun 2026 09:19:42 GMT</pubDate><category>Steganography</category><category>Phishing</category><category>WeTransfer</category><category>Malicious Images</category><category>MSI Branding</category></item><item><title>WordPress Sites Targeted by Malware Using Steam Profile Dead-Drops</title><link>https://runtimerebel.com/blog/wordpress-sites-targeted-by-malware-using-steam-profile-dead-drops</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-sites-targeted-by-malware-using-steam-profile-dead-drops</guid><description>Over 2,000 WordPress sites compromised in a campaign hiding C2 resolution data within Steam Community profiles. Technical breakdown of the evasion tactics.</description><pubDate>Mon, 01 Jun 2026 18:06:43 GMT</pubDate><category>WordPress</category><category>Steam Community</category><category>C2 Evasion</category><category>Steganography</category><category>Malware Analysis</category></item><item><title>LLM Text-in-Text Steganography: Emerging Covert Channel Risks</title><link>https://runtimerebel.com/blog/llm-text-in-text-steganography-emerging-covert-channel-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/llm-text-in-text-steganography-emerging-covert-channel-risks</guid><description>Analysis of how Large Language Models enable sophisticated text-in-text steganography for covert communication, data exfiltration, and C2 operations.</description><pubDate>Mon, 11 May 2026 13:11:36 GMT</pubDate><category>LLM</category><category>Steganography</category><category>Data Exfiltration</category><category>AI Security</category><category>Covert Channels</category></item><item><title>Malware Delivery via Malicious .WAV Files — Technical Analysis</title><link>https://runtimerebel.com/blog/malware-delivery-via-malicious-wav-files-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/malware-delivery-via-malicious-wav-files-technical-analysis</guid><description>Security analysts identify .WAV audio files being used to hide malicious payloads. Learn how steganography allows attackers to bypass perimeter security.</description><pubDate>Tue, 21 Apr 2026 08:45:41 GMT</pubDate><category>Steganography</category><category>Wav Malware</category><category>Powershell Obfuscation</category><category>APT32</category><category>Malware Delivery</category></item><item><title>Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware</title><link>https://runtimerebel.com/blog/backdoored-telnyx-pypi-package-uses-steganography-to-deliver-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/backdoored-telnyx-pypi-package-uses-steganography-to-deliver-malware</guid><description>Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.</description><pubDate>Sat, 28 Mar 2026 00:36:31 GMT</pubDate><category>PyPI</category><category>Telnyx</category><category>Steganography</category><category>Infostealer</category><category>TeamPCP</category><category>Python Security</category></item><item><title>Telnyx PyPI Package Compromised by TeamPCP via Steganography</title><link>https://runtimerebel.com/blog/telnyx-pypi-package-compromised-by-teampcp-via-steganography</link><guid isPermaLink="true">https://runtimerebel.com/blog/telnyx-pypi-package-compromised-by-teampcp-via-steganography</guid><description>TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.</description><pubDate>Fri, 27 Mar 2026 20:15:00 GMT</pubDate><category>Telnyx</category><category>PyPI</category><category>TeamPCP</category><category>Python</category><category>Steganography</category><category>Credential Theft</category></item></channel></rss>