[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f87Uy1mFZRune1YJADQmdTu6bJbJAE3Byr13v97L-dlA":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"adb45b12-d847-4d4f-be3e-c84c383db61e","Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2","transparent-tribe-deploys-new-rust-backdoor-using-private-github-repositories-fo-eb5aad","The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation","The Pakistan-aligned threat group Transparent Tribe (APT36) is targeting government and defense entities in India and Afghanistan with new tools like RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. Notably, the group is leveraging private GitHub repositories for command-and-control (C2) communications and using typosquatted domains to distribute malicious payloads.","Transparent Tribe uses new Rust malware and GitHub for C2 in attacks on India and Afghanistan.","Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 Ravie LakshmananSep 18, 2026Malware \u002F Cyber Espionage The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation RapidRust. \"APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan,\" Sudeep Singh, senior manager of APT Research at Zscaler ThreatLabz, said in a technical report published this week. The discovery comes a little over a month after Acronis Threat Research Unit (TRU) tied the long-running persistent threat group to another campaign aimed at Afghan telecom providers and South Asian critical infrastructure organizations using a backdoor called PATCHCORD. A notable aspect of the campaign is the threat actor's use of private GitHub repositories for command-and-control (C2) and the registration of typosquatted domains impersonating popular Indian news organizations like The Print and India Today to host malicious PowerShell scripts and payloads - theprints[.]org, which mimics The Print (\"theprint[.]in\") indiatodays[.]org, which mimics India Today (\"indiatoday[.]in\") Among the four newly identified malware families, one is a backdoor, another is a lateral movement utility, while the remaining two are file-stealing programs designed for Windows and Linux systems. RUSTYSHADE, as the name implies, is a Rust-based backdoor that makes use of attacker-controlled private GitHub repositories for encrypted C2 communications. It shares some level of functionality overlap with GITSHELLPAD, a Golang implant that was observed in September 2025 in connection with a campaign known as Gopher Strike. Specifically, the malware parses and writes certain files in the private GitHub repository for bidirectional communication using the GitHub REST API. The names of the files are below - command.txt, for storing encrypted C2 commands results.txt, for storing encrypted command output info.txt, to store system reconnaissance data heartbeat.txt, for keepalive beaconing to confirm active infection screenshot.png, for encrypted desktop screenshot webcam_photo.jpg, for encrypted webcam capture download.bin, for encrypted exfiltrated file contents The commands allow RUSTYSHADE to take screenshots, capture a webcam photo, perform file operations, and run commands in the background. As part of post-compromise activity, the threat actor has been observed fetching a file stealer from an attacker-controlled GitHub gist that comes in two variants for targeting both Windows and Linux environments - PSNATCH, a PowerShell stealer that recursively scans preconfigured directories for Microsoft Office documents, images, archives, media, executables, scripts, and databases that were modified within the last three months and exfiltrates them to a private repository named after the infected machine. The file collection is limited to 1 GB per file and 5 GB per execution. BASHNATCH, a bash script similar to PSNATCH that targets Linux systems Perhaps the most interesting of the lot is RUSTYMOVE, a lightweight 64-bit Windows USB propagation tool developed in Rust. Its main responsibility is to continuously monitor for external removable media using a PowerShell script and copy two pre-staged malicious files to the root directory of each detected external drive - DriverInstaller.zip, which contains RUSTYSHADE DocScanner-11-Aug-2026-5-37pm.pdf.LNK, which is suspected to contain a command to execute RUSTYSHADE after extraction Post-compromise activity from APT36 operators involves system, user, and network reconnaissance, followed by the deployment of next-stage payloads. A significant portion of the actions took place between August 20 and September 1, 2026, with the C2 commands issued only between 4 a.m. and 11 a.m. UTC and only on weekdays. \"This campaign demonstrates that APT36 continues to target government and defense entities in India and Afghanistan while maintaining high operational tempo and evolving TTPs,\" Singh said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cyber espionage, linux, Malware, Nation-State, Windows Security ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks When the Whole Company Adopts AI: What It Does to Your SOC Your Critical Vulnerabilities Might Not Be Your Biggest Risk What It Took to Reach 1 Billion Build Manifests US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries Why Are So Many Security Professionals Keeping Breaches Quiet? The Economics of Dwell Time and Why AI Native SIEM Changes the Equation ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Ftransparent-tribe-deploys-new-rust.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjhBM0nXgCLpwEyXmAdxLO_GatYww1Cem0yuGGqhmMwCB5N8w-TeoMm7jV4SbH4hjfYmxctUjyPiSlR3Caj2cSu7L_1nxTzg5xtfJrxhq5y0elL7yh8J2S5lakpnTbck3XhMVB1iG3obibSh64E8z877YcECkeJBs_rrZARXefKDeYQJ9Nf2u8pnxD0gEnx\u002Fs1600\u002Frust-malware.jpg","2026-09-18T15:24:16+00:00","2026-09-18T16:00:06.901423+00:00",9,[18,21,23,25,28,30],{"name":19,"type":20},"Transparent Tribe","threat_actor",{"name":22,"type":20},"APT36",{"name":24,"type":20},"Earth Karkaddan",{"name":26,"type":27},"RUSTYSHADE","product",{"name":29,"type":27},"RUSTYMOVE",{"name":31,"type":27},"PSNATCH","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":32,"icon":34,"name":35,"slug":36},null,"Threat Intelligence","threat-intelligence",[38,43,48],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[54,58,61,65,68,71,74,77,80,83,86,89,92,95,98,101,104,107,110,113],{"type":55,"value":56,"context":57},"domain","theprints[.]org","Typosquatted domain impersonating The Print for C2\u002Fpayload hosting.",{"type":55,"value":59,"context":60},"indiatodays[.]org","Typosquatted domain impersonating India Today for C2\u002Fpayload hosting.",{"type":62,"value":63,"context":64},"mitre_attack","T1071.001","Application Layer Protocol: Web Protocols (GitHub API usage for C2)",{"type":62,"value":66,"context":67},"T1041","Exfiltration Over C2 Channel (GitHub repositories for C2)",{"type":62,"value":69,"context":70},"T1573.002","Encrypted Channel: Asymmetric Cryptography (Used in RUSTYSHADE C2)",{"type":62,"value":72,"context":73},"T1048","Exfiltration Over Alternative Protocol (GitHub REST API)",{"type":62,"value":75,"context":76},"T1071","Application Layer Protocol (GitHub API)",{"type":62,"value":78,"context":79},"T1059.001","Command and Scripting Interpreter: PowerShell (PSNATCH)",{"type":62,"value":81,"context":82},"T1059.004","Command and Scripting Interpreter: Unix Shell (BASHNATCH)",{"type":62,"value":84,"context":85},"T1021.001","Remote System Discovery (Implied by lateral movement and reconnaissance)",{"type":62,"value":87,"context":88},"T1135","Network Share Discovery (Implied by lateral movement and file exfiltration)",{"type":62,"value":90,"context":91},"T1005","Data from Local System (PSNATCH file exfiltration)",{"type":62,"value":93,"context":94},"T1027","Obfuscated Files or Information (Implied by encrypted C2)",{"type":62,"value":96,"context":97},"T1105","Ingress Tool Transfer (Fetching file stealers from GitHub gist)",{"type":62,"value":99,"context":100},"T1571","Non-Standard Port (Implied by GitHub API usage)",{"type":62,"value":102,"context":103},"T1071.004","Application Layer Protocol: DNS (Implied by domain usage)",{"type":62,"value":105,"context":106},"T1566.002","Phishing: Spearphishing Attachment (Implied by malicious scripts\u002Fpayloads)",{"type":62,"value":108,"context":109},"T1204.002","User Execution: Malicious File (Implied by LNK file execution)",{"type":62,"value":111,"context":112},"T1071.002","Application Layer Protocol: HTTP\u002FS (GitHub REST API)",{"type":62,"value":114,"context":115},"T1219","Remote Access Software (RUSTYSHADE backdoor functionality)"]