<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Ukraine</title><description>Cybersecurity articles tagged #Ukraine on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Zimbra Zero-Day Exploited by Laundry Bear Against US &amp; Ukraine</title><link>https://runtimerebel.com/blog/zimbra-zero-day-exploited-by-laundry-bear-against-us-ukraine</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-zero-day-exploited-by-laundry-bear-against-us-ukraine</guid><description>Russian state-sponsored group &apos;Laundry Bear&apos; exploits a Zimbra zero-day via &apos;half-click&apos; phishing, targeting US and Ukrainian entities for credential theft and backdoor…</description><pubDate>Fri, 24 Jul 2026 02:47:14 GMT</pubDate><category>Laundry Bear</category><category>Zimbra</category><category>Zero-Day</category><category>Phishing</category><category>US</category><category>Ukraine</category><category>State Sponsored</category></item><item><title>Russian Intelligence Hijacks IP Cameras to Track NATO Logistics</title><link>https://runtimerebel.com/blog/russian-intelligence-hijacks-ip-cameras-to-track-nato-logistics</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-intelligence-hijacks-ip-cameras-to-track-nato-logistics</guid><description>Russian intelligence services are hijacking security cameras to monitor military logistics and troop movements throughout NATO member states and Ukraine.</description><pubDate>Mon, 20 Jul 2026 14:11:56 GMT</pubDate><category>Russian Intelligence</category><category>IP Cameras</category><category>NATO</category><category>Ukraine</category><category>Military Logistics</category><category>AIVD</category><category>MIVD</category></item><item><title>UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware</title><link>https://runtimerebel.com/blog/uac-0145-clickfix-strategy-how-sandworm-targets-ukraine-with-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uac-0145-clickfix-strategy-how-sandworm-targets-ukraine-with-malware</guid><description>Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.</description><pubDate>Sun, 19 Jul 2026 16:59:50 GMT</pubDate><category>UAC 0145</category><category>Sandworm</category><category>ClickFix</category><category>Ukraine</category><category>Malware</category><category>Phishing</category></item><item><title>Russian Intelligence Steals Messaging Credentials via SMS Lures</title><link>https://runtimerebel.com/blog/russian-intelligence-steals-messaging-credentials-via-sms-lures</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-intelligence-steals-messaging-credentials-via-sms-lures</guid><description>Ukraine and the FBI expose a long-running Russian intelligence campaign using fake support messages to compromise officials&apos; messaging accounts.</description><pubDate>Sat, 27 Jun 2026 20:29:25 GMT</pubDate><category>Russian Intelligence</category><category>SSU</category><category>FBI</category><category>Phishing</category><category>Messaging Security</category><category>Ukraine</category></item><item><title>Turla&apos;s STOCKSTAY Backdoor: Analysis of Campaigns &amp; WinRAR Exploit</title><link>https://runtimerebel.com/blog/turla-s-stockstay-backdoor-analysis-of-campaigns-winrar-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/turla-s-stockstay-backdoor-analysis-of-campaigns-winrar-exploit</guid><description>Google Threat Intelligence details STOCKSTAY, Turla&apos;s .NET backdoor for espionage targeting Ukraine and Europe, leveraging RDP &amp; CVE-2025-8088.</description><pubDate>Fri, 26 Jun 2026 09:21:08 GMT</pubDate><category>Turla</category><category>STOCKSTAY</category><category>KAZUAR</category><category>APT</category><category>Cyber Espionage</category><category>Ukraine</category><category>Government</category><category>Military</category><category>CVE-2025-8088</category><category>WinRAR</category><category>NET Malware</category><category>FSB</category></item><item><title>Russian APT Gamaredon Upgrades UAC-0010 Malware Arsenal</title><link>https://runtimerebel.com/blog/russian-apt-gamaredon-upgrades-uac-0010-malware-arsenal</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-apt-gamaredon-upgrades-uac-0010-malware-arsenal</guid><description>Analysis of Russian APT Gamaredon&apos;s (UAC-0010) upgraded arsenal, featuring stealthier Pterodo malware loading and volatile C2 infrastructure rotation.</description><pubDate>Fri, 26 Jun 2026 09:19:28 GMT</pubDate><category>Gamaredon</category><category>UAC 0010</category><category>Pterodo</category><category>Ukraine</category><category>FSB</category></item><item><title>Turla APT Deploys StockStay Backdoor in Ukraine Espionage Campaign</title><link>https://runtimerebel.com/blog/turla-apt-deploys-stockstay-backdoor-in-ukraine-espionage-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/turla-apt-deploys-stockstay-backdoor-in-ukraine-espionage-campaign</guid><description>Russian APT Turla targets Ukrainian government and military entities with the custom StockStay backdoor for persistent access and cyber espionage.</description><pubDate>Fri, 26 Jun 2026 09:18:02 GMT</pubDate><category>Turla</category><category>STOCKSTAY</category><category>Ukraine</category><category>Espionage</category><category>Russian APT</category><category>Malware</category></item><item><title>Turla Deploys New STOCKSTAY Backdoor in Ukraine Espionage Operations</title><link>https://runtimerebel.com/blog/turla-deploys-new-stockstay-backdoor-in-ukraine-espionage-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/turla-deploys-new-stockstay-backdoor-in-ukraine-espionage-operations</guid><description>Google identifies STOCKSTAY, a new .NET backdoor by Russian actor Turla targeting Ukrainian military and Italian foreign policy interests via Windows systems.</description><pubDate>Fri, 26 Jun 2026 09:17:20 GMT</pubDate><category>Turla</category><category>STOCKSTAY</category><category>Ukraine</category><category>Espionage</category><category>TAG 70</category><category>KRYPTON</category><category>NET</category></item><item><title>CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw</title><link>https://runtimerebel.com/blog/cve-2023-38831-russian-apts-target-ukraine-via-winrar-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-38831-russian-apts-target-ukraine-via-winrar-flaw</guid><description>Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.</description><pubDate>Tue, 09 Jun 2026 17:01:57 GMT</pubDate><category>CVE-2023-38831</category><category>WinRAR</category><category>APT28</category><category>Sandworm</category><category>Ukraine</category></item><item><title>CVE-2025-8088: Russia-Aligned Groups Exploit WinRAR Flaw in Ukraine</title><link>https://runtimerebel.com/blog/cve-2025-8088-russia-aligned-groups-exploit-winrar-flaw-in-ukraine</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-8088-russia-aligned-groups-exploit-winrar-flaw-in-ukraine</guid><description>Russia-linked actors Earth Dahu and UAC-0226 exploit the CVE-2025-8088 WinRAR path traversal flaw to deploy info-stealers against Ukrainian organizations.</description><pubDate>Tue, 09 Jun 2026 13:07:42 GMT</pubDate><category>CVE-2025-8088</category><category>Gamaredon</category><category>WinRAR</category><category>Earth Dahu</category><category>UAC 0226</category><category>Ukraine</category></item><item><title>Gamaredon Exploits WinRAR CVE-2025-8088 to Target Ukraine</title><link>https://runtimerebel.com/blog/gamaredon-exploits-winrar-cve-2025-8088-to-target-ukraine</link><guid isPermaLink="true">https://runtimerebel.com/blog/gamaredon-exploits-winrar-cve-2025-8088-to-target-ukraine</guid><description>Russian threat actor Gamaredon weaponizes a WinRAR path traversal flaw to deploy GammaWorm and GammaSteel malware against Ukrainian entities.</description><pubDate>Tue, 02 Jun 2026 21:09:37 GMT</pubDate><category>Gamaredon</category><category>CVE-2025-8088</category><category>WinRAR</category><category>Ukraine</category><category>GammaSteel</category><category>GammaWorm</category></item><item><title>GREYVIBE: Russian Actor&apos;s AI-Powered Cyberattacks Target Ukraine</title><link>https://runtimerebel.com/blog/greyvibe-russian-actor-s-ai-powered-cyberattacks-target-ukraine</link><guid isPermaLink="true">https://runtimerebel.com/blog/greyvibe-russian-actor-s-ai-powered-cyberattacks-target-ukraine</guid><description>Analysis of GREYVIBE, a newly discovered Russian-linked threat actor utilizing AI-powered techniques to target Ukrainian entities since August 2025.</description><pubDate>Fri, 29 May 2026 13:16:34 GMT</pubDate><category>GREYVIBE</category><category>Ukraine</category><category>Russia Linked</category><category>AI Powered Attacks</category><category>WithSecure</category></item><item><title>GreyVibe Actor Leverages AI Lures to Target Ukrainian Entities</title><link>https://runtimerebel.com/blog/greyvibe-actor-leverages-ai-lures-to-target-ukrainian-entities</link><guid isPermaLink="true">https://runtimerebel.com/blog/greyvibe-actor-leverages-ai-lures-to-target-ukrainian-entities</guid><description>Russian threat cluster GreyVibe uses ChatGPT and Gemini to automate highly targeted phishing lures and deploy custom malware against Ukrainian targets.</description><pubDate>Fri, 29 May 2026 05:33:03 GMT</pubDate><category>GREYVIBE</category><category>UAC 0149</category><category>Ukraine</category><category>AI Driven Attacks</category><category>Social Engineering</category></item><item><title>Ghostwriter Targets Ukraine Government with Prometheus Phishing</title><link>https://runtimerebel.com/blog/ghostwriter-targets-ukraine-government-with-prometheus-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghostwriter-targets-ukraine-government-with-prometheus-phishing</guid><description>Belarus-aligned Ghostwriter (UAC-0057) targets Ukrainian government entities with Prometheus-themed phishing emails to deploy sophisticated malware.</description><pubDate>Fri, 22 May 2026 20:37:28 GMT</pubDate><category>Ghostwriter</category><category>UAC 0057</category><category>UNC1151</category><category>Ukraine</category><category>Government</category><category>Phishing</category><category>Prometheus</category><category>CERT UA</category><category>APT</category></item><item><title>FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing</title><link>https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</guid><description>Belarussian APT &apos;FrostyNeighbor&apos; is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…</description><pubDate>Thu, 14 May 2026 20:38:13 GMT</pubDate><category>FrostyNeighbor</category><category>APT</category><category>Belarus</category><category>Poland</category><category>Ukraine</category><category>Espionage</category><category>Spear Phishing</category><category>Government</category><category>Nation State</category></item><item><title>Ghostwriter Targets Ukraine with Geofenced PDF Phishing &amp; Cobalt Strike</title><link>https://runtimerebel.com/blog/ghostwriter-targets-ukraine-with-geofenced-pdf-phishing-cobalt-strike</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghostwriter-targets-ukraine-with-geofenced-pdf-phishing-cobalt-strike</guid><description>Ghostwriter (UAC-0057) leverages geofenced PDF phishing to deliver Cobalt Strike against Ukrainian government entities, combining espionage and influence.</description><pubDate>Thu, 14 May 2026 16:45:40 GMT</pubDate><category>Ghostwriter</category><category>UAC 0057</category><category>Ukraine</category><category>Phishing</category><category>Cobalt Strike</category><category>APT</category></item><item><title>UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware</title><link>https://runtimerebel.com/blog/uac-0247-targets-ukrainian-healthcare-via-data-theft-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uac-0247-targets-ukrainian-healthcare-via-data-theft-malware</guid><description>UAC-0247 is targeting Ukrainian clinics and government entities using malware designed to steal data from WhatsApp and Chromium-based browsers.</description><pubDate>Thu, 16 Apr 2026 08:40:22 GMT</pubDate><category>UAC 0247</category><category>Ukraine</category><category>Healthcare Security</category><category>Information Stealer</category><category>Data Theft</category></item><item><title>AgingFly Malware: Credential Theft Operations Against Ukraine</title><link>https://runtimerebel.com/blog/agingfly-malware-credential-theft-operations-against-ukraine</link><guid isPermaLink="true">https://runtimerebel.com/blog/agingfly-malware-credential-theft-operations-against-ukraine</guid><description>Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…</description><pubDate>Thu, 16 Apr 2026 00:47:01 GMT</pubDate><category>AgingFly</category><category>Malware</category><category>Ukraine</category><category>Credential Theft</category><category>Chromium</category><category>WhatsApp</category><category>Government</category><category>Hospitals</category></item><item><title>APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware</title><link>https://runtimerebel.com/blog/apt28-targets-ukraine-and-nato-allies-with-new-prismex-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-targets-ukraine-and-nato-allies-with-new-prismex-malware</guid><description>APT28 (Forest Blizzard) deploys the undocumented PRISMEX malware suite against Ukraine and NATO, utilizing COM hijacking and cloud-based C2 infrastructure.</description><pubDate>Wed, 08 Apr 2026 16:31:54 GMT</pubDate><category>APT28</category><category>PRISMEX</category><category>Forest Blizzard</category><category>Ukraine</category><category>NATO</category><category>COM Hijacking</category></item><item><title>APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit</title><link>https://runtimerebel.com/blog/apt28-targets-ukraine-via-cve-2024-45519-zimbra-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-targets-ukraine-via-cve-2024-45519-zimbra-exploit</guid><description>Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.</description><pubDate>Thu, 19 Mar 2026 16:25:10 GMT</pubDate><category>APT28</category><category>Zimbra</category><category>CVE-2024-45519</category><category>Ukraine</category><category>SSSCIP</category><category>GRU</category></item><item><title>DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users</title><link>https://runtimerebel.com/blog/darksword-iphone-exploit-kit-zero-day-attacks-on-ios-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/darksword-iphone-exploit-kit-zero-day-attacks-on-ios-users</guid><description>DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…</description><pubDate>Thu, 19 Mar 2026 00:37:39 GMT</pubDate><category>DarkSword</category><category>iOS</category><category>iPhone</category><category>Zero-Day</category><category>Exploit Kit</category><category>Nation State</category><category>Cybercrime</category><category>Espionage</category><category>Turkey</category><category>Saudi Arabia</category><category>Malaysia</category><category>Ukraine</category></item></channel></rss>