<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CloudTrex Blog</title><description>Notes on cyber security, threat intelligence and cloud defence from the team behind ThreatFeed.</description><link>https://blog.cloudtrex.eu/</link><language>en</language><item><title>SmartLoader: Lua-based malware delivered through cloned GitHub repositories</title><link>https://blog.cloudtrex.eu/smartloader-lua-malware-cloned-github-repos/</link><guid isPermaLink="true">https://blog.cloudtrex.eu/smartloader-lua-malware-cloned-github-repos/</guid><description>Stage-by-stage analysis of a SmartLoader campaign: cloned GitHub repos, a renamed LuaJIT runtime, EtherHiding C2 on Polygon, and a stealer that bypasses Chrome App-Bound Encryption.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate><category>Malware Analysis</category><category>SmartLoader</category><category>GitHub</category><category>EtherHiding</category><category>Infostealer</category></item></channel></rss>