Zscaler ThreatLabz: APT36 Operation RapidRust — RUSTYSHADE GitHub C2 + RUSTYMOVE air-gap tool
Zscaler ThreatLabz (blog 16 September 2026; The Hacker News wire 18 September) tracks Pakistan-nexus APT36 (Transparent Tribe / Earth Karkaddan) activity in August 2026 as Operation RapidRust against government and defence entities in India and Afghanistan. New tooling: RUSTYSHADE — 64-bit Windows Rust backdoor using attacker-controlled private GitHub repos via REST API for C2 (hardcoded PAT; AES-256-GCM with key from SHA256(PAT)); RUSTYMOVE — post-compromise copier that stages malware onto removable media to reach air-gapped networks; PSNATCH — PowerShell file stealer exfiltrating matched extensions to private GitHub; BASHNATCH — bash analogue for Linux. Delivery includes typosquatted Indian news domains staging PowerShell; sample post-compromise wget of DriverInstaller.zip from Backblaze B2. Related to earlier GOGITTER/GITSHELLPAD GitHub-C2 tradecraft but Rust + encrypted C2. Primary: Zscaler ThreatLabz; wire: THN.
- Product
- APT36 tooling (RUSTYSHADE / RUSTYMOVE / PSNATCH / BASHNATCH) vs Windows and Linux endpoints
- Versions
- n/a (threat-actor malware; not a product CVE)
- Exploited in Australia?
- unknown
- Patch to
- Block untrusted GitHub PAT use from endpoints; monitor api.github.com repo content access from unusual hosts; restrict removable-media write on high-value systems; apply Zscaler/THN IoCs from the ThreatLabz post.
Primary: Zscaler ThreatLabz — Operation RapidRust / APT36 (16 Sep 2026) · The Hacker News — Transparent Tribe Rust backdoor / private GitHub C2 (18 Sep 2026)
