APT36 Abuses Private GitHub Repos for Stealthy C2 Communications
Transparent Tribe (APT36) is exploiting the inherent trust organizations place in legitimate platforms like GitHub by using private repositories as command-and-control infrastructure, effectively blending malicious traffic with normal developer activity. Typosquatted domains further weaponize user inattention to deliver novel Rust-based backdoors (RUSTYSHADE, RUSTYMOVE) and bash/PowerShell stealers. This matters because traffic to trusted platforms like GitHub often bypasses traditional perimeter defenses and content inspection tools, giving attackers a persistent, low-visibility foothold. Organizations that lack granular egress filtering and behavioral monitoring of outbound connections to code-hosting platforms are particularly exposed to this technique.
Tactical Insight
Immediate actions
- Block or strictly control outbound connections to GitHub API endpoints from non-developer systems and servers using firewall or proxy allowlisting.
- Deploy DNS filtering and threat intelligence feeds to detect and block typosquatted domains before payloads are delivered.
- Hunt for indicators of compromise (IOCs) related to RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH across endpoints and network logs.
Detection measures
- Enable deep packet inspection and TLS decryption on egress traffic to detect anomalous use of legitimate platforms (GitHub, Pastebin, etc.) for C2 beaconing.
- Configure SIEM rules to alert on unusual processes making outbound HTTPS calls to code-hosting repositories, especially from government or defense workstations.
- Monitor for execution of Rust-compiled binaries and unexpected shell scripting activity (bash/PowerShell) on endpoints.
Long-term improvements
- Implement strict application allowlisting to prevent unauthorized or unknown executables (including novel Rust binaries) from running on sensitive systems.
- Enforce network segmentation so that government and defense endpoints have no direct internet access, routing all traffic through authenticated, inspected proxies.
- Conduct regular threat-hunting exercises focused on living-off-trusted-sites (LOTS) techniques and APT TTPs mapped to MITRE ATT&CK for nation-state actors.