Operation RapidRust shows that Transparent Tribe, also tracked as APT36 or Earth Karkaddan, continues to upgrade its cyber-espionage capabilities against government and defense organizations in India and Afghanistan. Zscaler ThreatLabz's September 16, 2026 report describes four previously undocumented tools: the RUSTYSHADE backdoor, the RUSTYMOVE removable-media propagation utility, and the PSNATCH and BASHNATCH file stealers.

APT36 and the Context Behind Operation RapidRust
APT36 is a Pakistan-linked threat group with a long record of espionage focused on South Asia. In August 2026, ThreatLabz observed the group targeting government and defense organizations in India and Afghanistan. The discovery follows earlier campaigns involving GITSHELLPAD and PATCHCORD, showing sustained operational tempo and continuing tool changes intended to reduce detection.
The campaign infrastructure combines legitimate services with attacker-controlled domains. APT36 registered theprints[.]org and indiatodays[.]org, impersonating The Print and India Today, to stage PowerShell code and malicious payloads. Backblaze distributed tools, while private GitHub repositories served as command channels and destinations for stolen data.
RUSTYSHADE Turns Private GitHub Repositories Into Command Servers
RUSTYSHADE is a 64-bit Windows backdoor written in Rust. It calls the GitHub REST API, authenticates with a personal access token embedded in the executable, and exchanges data with an attacker-controlled private repository. Commands and results use AES-256-GCM encryption, with a 32-byte key derived from the token's SHA-256 hash, making traffic resemble normal GitHub activity while protecting its contents.
The files command.txt, results.txt, info.txt, and heartbeat.txt carry commands, results, reconnaissance data, and keepalive signals. RUSTYSHADE can also capture screenshots and webcam images, enumerate drives, download files, and run background commands. Using a popular platform for C2 makes domain-wide blocking difficult without disrupting legitimate development.
Data-Theft Tools for Windows and Linux
PSNATCH is a PowerShell script that scans Desktop, Downloads, Documents, OneDrive, and multiple drives for Office documents, images, archives, databases, source code, and other data. It prioritizes recently modified files, limits collection to 1 GB per file and 5 GB per run, then uploads data to a private GitHub repository named after the infected computer.
BASHNATCH applies the same approach to Linux. Both tools keep a local tracking file so later runs send only new or changed files. Incremental uploads reduce traffic spikes and support prolonged collection.
RUSTYMOVE Carries the Threat Into Air-Gapped Networks
RUSTYMOVE is a 64-bit Windows utility written in Rust that continuously detects USB drives, memory cards, and external storage. When it finds a new device, it copies DriverInstaller.zip containing RUSTYSHADE and an LNK file disguised as a PDF to the root directory. ThreatLabz assesses with high confidence that the LNK is designed to launch the backdoor after extraction.
This propagation method is especially relevant to government and defense environments where removable media often transfers data into air-gapped networks. RUSTYMOVE persists through a scheduled task named like a OneDrive updater, but its simple behavior and hardcoded paths suggest an early stage of development.
Timeline and Post-Compromise Activity
Most observed command activity occurred from August 20 to September 1, 2026, only on weekdays and mainly between 4:00 and 11:00 UTC. After gaining access, operators examined users, privileges, processes, network configuration, and geolocation; swept internal networks, enumerated systems and SMB shares, tested IPC$ connections, and probed ports 445 and 135 to prepare lateral movement.
The group also created scheduled tasks disguised as Microsoft Edge or OneDrive components, deployed follow-on payloads, and deleted old tool files to reduce traces. Timing patterns do not independently prove operator identity, but they provide useful behavioral data for threat hunting.
Technical Impact and Organizational Risk
Operation RapidRust combines reconnaissance, persistence, cross-platform data collection, and removable-media propagation. Left undetected, it can expose sensitive documents, screenshots, webcam data, and internal network information while creating a bridge to other computers, including systems without direct internet access.
The use of GitHub and Backblaze also creates a security-versus-operations tradeoff. Blanket blocking can disrupt work, while domain reputation alone will miss malicious traffic. Organizations need identity controls, API visibility, process behavior monitoring, and data-loss prevention together.
Defensive Recommendations
- Review access to the GitHub Contents API from non-development systems, especially unfamiliar processes using embedded tokens and creating private repositories named after computers.
- Hunt for scheduled tasks impersonating OneDrive or Edge, DriverInstaller.zip, the SmartUploader string, and PowerShell activity downloading code from domains that resemble news outlets.
- Restrict unnecessary PowerShell use, enable Script Block logging and AMSI, and forward logs to centralized monitoring.
- Apply role-based USB controls and scan LNK files and archives before allowing transfer into air-gapped networks.
- Monitor network scanning, unusual SMB or RPC activity, and large numbers of files being read and sent to source-code hosting services.
- Rotate or revoke related credentials after detecting compromise, isolate affected systems, and investigate both Windows and Linux hosts.
Lessons From the Campaign
APT36 does not rely on one technique. It combines legitimate cloud services, lookalike domains, Rust malware, and removable media into a unified operation. Effective defense must therefore track behavior across the attack lifecycle instead of blocking a single address or signature.
In sensitive environments, removable-media policy and visibility into cloud development services should be treated as core security controls. Network segmentation, least privilege, strong authentication, and regular response exercises reduce the blast radius when an endpoint is compromised.
VNCyberS compiled from Zscaler ThreatLabz and The Hacker News















