<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.gridinsoft.com/noir-wallet-drainer-dns-permissions/</loc>
    <news:news>
      <news:publication>
        <news:name>Gridinsoft</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-09T15:03:40+00:00</news:publication_date>
      <news:title>Noir Wallet Drainer Uses DNS to Keep Fake Crypto Pages Working</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://blog.gridinsoft.com/fake-event-invitations-google-qr-phishing/</loc>
    <news:news>
      <news:publication>
        <news:name>Gridinsoft</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-09T09:14:25+00:00</news:publication_date>
      <news:title>Fake Event Invitations Turn QR Codes Into Google Phishing</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://blog.gridinsoft.com/nebula-fake-ai-sdk-windows-rat/</loc>
    <news:news>
      <news:publication>
        <news:name>Gridinsoft</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-08T15:05:15+00:00</news:publication_date>
      <news:title>NEBULA: Fake AI SDKs Install a Hidden Windows RAT</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://blog.gridinsoft.com/bluekit-phishing-stolen-session-access/</loc>
    <news:news>
      <news:publication>
        <news:name>Gridinsoft</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-10-08T09:03:23+00:00</news:publication_date>
      <news:title>BlueKit Phishing: A Stolen Session Can Outlast the Login</news:title>
    </news:news>
  </url>
</urlset>
