The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.
The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation RapidRust.
“APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan,” Sudeep Singh, senior manager of APT Research at Zscaler ThreatLabz, said in a technical report published this week.
The discovery comes a little over a month after Acronis Threat Research Unit (TRU) tied the long-running persistent threat group to another campaign aimed at Afghan telecom providers and South Asian critical infrastructure organizations using a backdoor called PATCHCORD.
A notable aspect of the campaign is the threat actor’s use of private GitHub repositories for command-and-control (C2) and the registration of typosquatted domains impersonating popular Indian news organizations like The Print and India Today to host malicious PowerShell scripts and payloads –
Among the four newly identified malware families, one is a backdoor, another is a lateral movement utility, while the remaining two are file-stealing programs designed for Windows and Linux systems.
RUSTYSHADE, as the name implies, is a Rust-based backdoor that makes use of attacker-controlled private GitHub repositories for encrypted C2 communications. It shares some level of functionality overlap with GITSHELLPAD, a Golang implant that was observed in September 2025 in connection with a campaign known as Gopher Strike.
Specifically, the malware parses and writes certain files in the private GitHub repository for bidirectional communication using the GitHub REST API. The names of the files are below –
The commands allow RUSTYSHADE to take screenshots, capture a webcam photo, perform file operations, and run commands in the background.
As part of post-compromise activity, the threat actor has been observed fetching a file stealer from an attacker-controlled GitHub gist that comes in two variants for targeting both Windows and Linux environments –
Leave a Reply