<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Threat Actor</title><description>Cybersecurity articles tagged #Threat Actor on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Jewelbug APT: Dual-Motivation Espionage &amp; Crypto Heists</title><link>https://runtimerebel.com/blog/jewelbug-apt-dual-motivation-espionage-crypto-heists</link><guid isPermaLink="true">https://runtimerebel.com/blog/jewelbug-apt-dual-motivation-espionage-crypto-heists</guid><description>Jewelbug APT, a unique &apos;hackers-for-hire&apos; group, conducts state-sponsored espionage and financially motivated cryptocurrency heists from a single operational panel.</description><pubDate>Thu, 13 Aug 2026 16:47:11 GMT</pubDate><category>Cyber Espionage</category><category>Cryptocurrency Theft</category><category>Threat Actor</category><category>Financially Motivated</category><category>Jewelbug APT</category></item><item><title>DeepSeek AI &amp; Hermes Agent: Autonomous Server Exploitation</title><link>https://runtimerebel.com/blog/deepseek-ai-hermes-agent-autonomous-server-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/deepseek-ai-hermes-agent-autonomous-server-exploitation</guid><description>A threat actor is leveraging DeepSeek AI and the Hermes Agent for autonomous attacks against vulnerable, internet-exposed servers, demanding urgent defense.</description><pubDate>Fri, 31 Jul 2026 17:42:21 GMT</pubDate><category>DeepSeek AI</category><category>Hermes Agent</category><category>Autonomous Attack</category><category>AI in Hacking</category><category>Server Exploitation</category><category>Threat Actor</category></item><item><title>Google Gemini CLI Abused by &apos;bandcampro&apos; for Botnet Operations</title><link>https://runtimerebel.com/blog/google-gemini-cli-abused-by-bandcampro-for-botnet-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-cli-abused-by-bandcampro-for-botnet-operations</guid><description>Russian-speaking threat actor &apos;bandcampro&apos; is leveraging Google&apos;s Gemini CLI as a hacking agent and to command a small-scale botnet.</description><pubDate>Wed, 15 Jul 2026 21:05:52 GMT</pubDate><category>Bandcampro</category><category>Google Gemini CLI</category><category>AI Abuse</category><category>Botnet</category><category>Threat Actor</category><category>TTP</category></item><item><title>UNC6692 Leverages Teams, AWS S3 for Malware &amp; Cloud Abuse</title><link>https://runtimerebel.com/blog/unc6692-leverages-teams-aws-s3-for-malware-cloud-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6692-leverages-teams-aws-s3-for-malware-cloud-abuse</guid><description>Newly discovered threat actor UNC6692 combines social engineering via Microsoft Teams with custom &apos;Snow&apos; malware and AWS S3 cloud abuse in multi-pronged attacks.</description><pubDate>Mon, 27 Apr 2026 20:30:32 GMT</pubDate><category>UNC6692</category><category>Microsoft Teams</category><category>AWS S3</category><category>SNOW Malware</category><category>Social Engineering</category><category>Cloud Abuse</category><category>Threat Actor</category></item><item><title>The Gentlemen Ransomware Group: Rapid Escalation and Sophistication</title><link>https://runtimerebel.com/blog/the-gentlemen-ransomware-group-rapid-escalation-and-sophistication</link><guid isPermaLink="true">https://runtimerebel.com/blog/the-gentlemen-ransomware-group-rapid-escalation-and-sophistication</guid><description>An analysis of &apos;The Gentlemen&apos; ransomware group, highlighting their rapid operational scaling and sophisticated attack methods impacting organizations globally.</description><pubDate>Thu, 23 Apr 2026 00:46:56 GMT</pubDate><category>The Gentlemen</category><category>Ransomware</category><category>Threat Actor</category><category>Cybercrime</category></item><item><title>TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attacks-escalate-amidst-hacker-infighting</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attacks-escalate-amidst-hacker-infighting</guid><description>Runtime Rebel details how TeamPCP&apos;s supply chain attacks are leading to breaches, with ShinyHunters and Lapsus$ adding to the chaos.</description><pubDate>Fri, 03 Apr 2026 16:18:40 GMT</pubDate><category>TeamPCP</category><category>ShinyHunters</category><category>Lapsus</category><category>Supply Chain Attack</category><category>Breach</category><category>Threat Actor</category></item><item><title>Chinese Cyber Threat: Persistent Espionage in Critical Asian Sectors</title><link>https://runtimerebel.com/blog/chinese-cyber-threat-persistent-espionage-in-critical-asian-sectors</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-cyber-threat-persistent-espionage-in-critical-asian-sectors</guid><description>An undefined Chinese-speaking actor conducts long-term cyber espionage against critical Asian sectors using custom malware and living-off-the-land binaries.</description><pubDate>Mon, 09 Mar 2026 16:35:16 GMT</pubDate><category>Chinese APT</category><category>Espionage</category><category>Windows</category><category>Linux</category><category>LOTL</category><category>Custom Malware</category><category>Critical Infrastructure</category><category>Threat Actor</category></item><item><title>CyberStrikeAI Leveraged in AI-Driven FortiGate Attacks Across 55 Countries</title><link>https://runtimerebel.com/blog/cyberstrikeai-leveraged-in-ai-driven-fortigate-attacks-across-55-countries</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyberstrikeai-leveraged-in-ai-driven-fortigate-attacks-across-55-countries</guid><description>An open-source AI platform, CyberStrikeAI, is deployed in sophisticated, AI-driven attacks targeting Fortinet FortiGate appliances globally.</description><pubDate>Tue, 03 Mar 2026 16:22:24 GMT</pubDate><category>CyberStrikeAI</category><category>FortiGate</category><category>AI Driven Attacks</category><category>Team Cymru</category><category>Threat Actor</category><category>Open Source</category></item><item><title>BlackMesh Ransomware Group Pivots to Healthcare Infrastructure</title><link>https://runtimerebel.com/blog/ransomware-group-targets-healthcare</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransomware-group-targets-healthcare</guid><description>The BlackMesh ransomware syndicate has shifted targeting to hospitals and healthcare networks across North America and Europe, leveraging stolen VPN credentials and…</description><pubDate>Sat, 20 Jan 2024 00:00:00 GMT</pubDate><category>Ransomware</category><category>Healthcare</category><category>Threat Actor</category><category>Citrix Bleed</category><category>VPN</category></item></channel></rss>