<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Vishing</title><description>Cybersecurity articles tagged #Vishing on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Spring Ring Voice Phishing Targets Microsoft Teams Users</title><link>https://runtimerebel.com/blog/spring-ring-voice-phishing-targets-microsoft-teams-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/spring-ring-voice-phishing-targets-microsoft-teams-users</guid><description>Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.</description><pubDate>Tue, 01 Sep 2026 02:47:23 GMT</pubDate><category>Microsoft Teams</category><category>Vishing</category><category>Social Engineering</category><category>NTLM Relay</category><category>Spring Ring</category></item><item><title>ReliaQuest Thwarts ShinyHunters Social Engineering Attack on Okta SSO</title><link>https://runtimerebel.com/blog/reliaquest-thwarts-shinyhunters-social-engineering-attack-on-okta-sso</link><guid isPermaLink="true">https://runtimerebel.com/blog/reliaquest-thwarts-shinyhunters-social-engineering-attack-on-okta-sso</guid><description>ReliaQuest confirms a social engineering attack by ShinyHunters targeting an employee&apos;s Okta SSO, blocked from accessing applications or customer data.</description><pubDate>Mon, 24 Aug 2026 16:25:26 GMT</pubDate><category>ShinyHunters</category><category>Social Engineering</category><category>Phishing</category><category>Vishing</category><category>Okta</category></item><item><title>UNC6671 Targets Financial Sector via Vishing and AiTM Phishing</title><link>https://runtimerebel.com/blog/unc6671-targets-financial-sector-via-vishing-and-aitm-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6671-targets-financial-sector-via-vishing-and-aitm-phishing</guid><description>UNC6671, linked to BlackFile, exploits vishing and AiTM phishing against financial firms for cloud data theft and extortion.</description><pubDate>Sun, 09 Aug 2026 16:23:40 GMT</pubDate><category>Vishing</category><category>Financial Sector</category><category>Data Theft</category><category>UNC6671</category><category>BlackFile</category></item><item><title>Microsoft 365 Entra Passkey Vishing Targets: Account Takeover Risk</title><link>https://runtimerebel.com/blog/microsoft-365-entra-passkey-vishing-targets-account-takeover-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-365-entra-passkey-vishing-targets-account-takeover-risk</guid><description>A sophisticated vishing campaign targets Microsoft 365 users, tricking them into enrolling malicious Entra passkeys for account takeover. Learn detection and prevention.</description><pubDate>Wed, 08 Jul 2026 17:39:23 GMT</pubDate><category>Microsoft 365</category><category>Entra</category><category>Passkey</category><category>Vishing</category><category>Social Engineering</category><category>Account Takeover</category></item><item><title>Silent Ransom Group Targets US Law Firms via Vishing and Intrusions</title><link>https://runtimerebel.com/blog/silent-ransom-group-targets-us-law-firms-via-vishing-and-intrusions</link><guid isPermaLink="true">https://runtimerebel.com/blog/silent-ransom-group-targets-us-law-firms-via-vishing-and-intrusions</guid><description>Silent Ransom Group (Luna Moth) targets US law firms using vishing and physical intrusions for data extortion. Technical analysis and mitigation strategies.</description><pubDate>Tue, 09 Jun 2026 05:28:46 GMT</pubDate><category>Silent Ransom Group</category><category>Luna Moth</category><category>Vishing</category><category>Law Firms</category><category>Extortion</category><category>Social Engineering</category></item><item><title>UNC3753: Vishing and Physical Intrusions Fuel U.S. Data Extortion</title><link>https://runtimerebel.com/blog/unc3753-vishing-and-physical-intrusions-fuel-u-s-data-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc3753-vishing-and-physical-intrusions-fuel-u-s-data-extortion</guid><description>Mandiant identifies UNC3753 targeting U.S. legal and financial sectors through sophisticated vishing and physical breaches to execute data theft extortion.</description><pubDate>Mon, 08 Jun 2026 09:43:30 GMT</pubDate><category>UNC3753</category><category>Vishing</category><category>Physical Security</category><category>Mandiant</category><category>Data Extortion</category><category>Financial Sector</category></item><item><title>UNC3753 Targets US Law Firms with Vishing &amp; Physical Intrusions</title><link>https://runtimerebel.com/blog/unc3753-targets-us-law-firms-with-vishing-physical-intrusions</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc3753-targets-us-law-firms-with-vishing-physical-intrusions</guid><description>UNC3753 (Luna Moth) leverages vishing and physical office intrusions to steal sensitive data from US law firms and professional services, leading to swift extortion.</description><pubDate>Fri, 05 Jun 2026 16:59:08 GMT</pubDate><category>UNC3753</category><category>Luna Moth</category><category>Silent Ransom Group</category><category>Vishing</category><category>Social Engineering</category><category>Data Theft</category><category>Extortion</category><category>Law Firms</category><category>Physical Intrusion</category><category>RMM</category><category>WinSCP</category><category>Rclone</category></item><item><title>Google Android Scam Detection: Real-Time AI Defense Against Fraud</title><link>https://runtimerebel.com/blog/google-android-scam-detection-real-time-ai-defense-against-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-android-scam-detection-real-time-ai-defense-against-fraud</guid><description>Google introduces AI-powered Scam Detection for Android, utilizing on-device Gemini Nano to identify fraud patterns and protect users from voice-based phishing.</description><pubDate>Wed, 03 Jun 2026 09:44:39 GMT</pubDate><category>Android</category><category>Google Gemini Nano</category><category>AI Deepfakes</category><category>Vishing</category><category>Mobile Security</category></item><item><title>BlackFile: Analyzing UNC6671 Vishing &amp; Cloud Data Extortion</title><link>https://runtimerebel.com/blog/blackfile-analyzing-unc6671-vishing-cloud-data-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/blackfile-analyzing-unc6671-vishing-cloud-data-extortion</guid><description>Examines UNC6671&apos;s BlackFile vishing, AiTM, and cloud data exfiltration tactics against Microsoft 365 &amp; Okta. Actionable mitigations included.</description><pubDate>Fri, 15 May 2026 20:32:33 GMT</pubDate><category>UNC6671</category><category>BlackFile</category><category>Vishing</category><category>AitM</category><category>Microsoft 365</category><category>Okta</category><category>SharePoint</category><category>OneDrive</category><category>Data Exfiltration</category><category>Extortion</category><category>Social Engineering</category></item><item><title>Cordial Spider and Snarky Spider: Rapid SaaS Extortion via Vishing</title><link>https://runtimerebel.com/blog/cordial-spider-and-snarky-spider-rapid-saas-extortion-via-vishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/cordial-spider-and-snarky-spider-rapid-saas-extortion-via-vishing</guid><description>Researchers identify Cordial Spider and Snarky Spider using vishing and SSO abuse to execute high-speed data theft within corporate SaaS environments.</description><pubDate>Fri, 01 May 2026 16:25:42 GMT</pubDate><category>CORDIAL SPIDER</category><category>SNARKY SPIDER</category><category>Vishing</category><category>SSO Abuse</category><category>UNC6671</category><category>UNC6661</category><category>SaaS Security</category></item><item><title>Fake IT Support Campaigns Deploy Customized Havoc C2 Payloads</title><link>https://runtimerebel.com/blog/fake-it-support-campaigns-deploy-customized-havoc-c2-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-it-support-campaigns-deploy-customized-havoc-c2-payloads</guid><description>Huntress identifies a new campaign using fake IT support lures and vishing to deploy Havoc C2 for data exfiltration and ransomware delivery.</description><pubDate>Tue, 03 Mar 2026 20:11:54 GMT</pubDate><category>Havoc C2</category><category>Social Engineering</category><category>Vishing</category><category>Huntress</category><category>Ransomware</category></item><item><title>SLH Recruits Women for $1,000 IT Help Desk Vishing Attacks</title><link>https://runtimerebel.com/blog/slh-recruits-women-for-1000-it-help-desk-vishing-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/slh-recruits-women-for-1000-it-help-desk-vishing-attacks</guid><description>Scattered LAPSUS$ Hunters (SLH) are offering financial incentives to recruit women for vishing campaigns targeting corporate IT help desks and IAM systems.</description><pubDate>Wed, 25 Feb 2026 16:30:53 GMT</pubDate><category>Scattered LAPSUS Hunters</category><category>Vishing</category><category>Social Engineering</category><category>IT Help Desk</category><category>IAM</category></item></channel></rss>