Back to all lessons
Awareness Lessons
3 weeks ago

APT36 Abuses Private GitHub Repos for Stealthy C2 Communications

Transparent Tribe (APT36) is exploiting the inherent trust organizations place in legitimate platforms like GitHub by using private repositories as command-and-control infrastructure, effectively blending malicious traffic with normal developer activity. Typosquatted domains further weaponize user inattention to deliver novel Rust-based backdoors (RUSTYSHADE, RUSTYMOVE) and bash/PowerShell stealers. This matters because traffic to trusted platforms like GitHub often bypasses traditional perimeter defenses and content inspection tools, giving attackers a persistent, low-visibility foothold. Organizations that lack granular egress filtering and behavioral monitoring of outbound connections to code-hosting platforms are particularly exposed to this technique.

Tactical Insight

Immediate actions

  • Block or strictly control outbound connections to GitHub API endpoints from non-developer systems and servers using firewall or proxy allowlisting.
  • Deploy DNS filtering and threat intelligence feeds to detect and block typosquatted domains before payloads are delivered.
  • Hunt for indicators of compromise (IOCs) related to RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH across endpoints and network logs.

Detection measures

  • Enable deep packet inspection and TLS decryption on egress traffic to detect anomalous use of legitimate platforms (GitHub, Pastebin, etc.) for C2 beaconing.
  • Configure SIEM rules to alert on unusual processes making outbound HTTPS calls to code-hosting repositories, especially from government or defense workstations.
  • Monitor for execution of Rust-compiled binaries and unexpected shell scripting activity (bash/PowerShell) on endpoints.

Long-term improvements

  • Implement strict application allowlisting to prevent unauthorized or unknown executables (including novel Rust binaries) from running on sensitive systems.
  • Enforce network segmentation so that government and defense endpoints have no direct internet access, routing all traffic through authenticated, inspected proxies.
  • Conduct regular threat-hunting exercises focused on living-off-trusted-sites (LOTS) techniques and APT TTPs mapped to MITRE ATT&CK for nation-state actors.