Skip to content

Security1 publisher2 min readPublished

APT36 hides Operation RapidRust command traffic inside private GitHub repositories

Zscaler ThreatLabz says the Pakistan-aligned group worked government and defense targets in India and Afghanistan with four undocumented tools, one of them a Rust backdoor that takes its orders from files in a private repo.

The Watch · Security desk

Illustration accompanying APT36 hides Operation RapidRust command traffic inside private GitHub repositories

What happened

  • Zscaler ThreatLabz attributes a new campaign against government and defense organizations in India and Afghanistan to the Pakistan-aligned group Transparent Tribe, also tracked as APT36.
  • Operation RapidRust runs four previously undocumented families: the Rust backdoor RUSTYSHADE, the Windows stealer PSNATCH, the Linux stealer BASHNATCH and the USB spreader RUSTYMOVE.
  • ThreatLabz observed the activity mainly between August 20 and September 1, 2026, with command traffic issued only on weekdays and only within specific UTC hours.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Indicator lists of attacker-registered C2 domains do not touch this channel. The only network artifact at the command stage is HTTPS to a host that engineering organizations allow deliberately.
  • exposure Targeting recently modified documents plus webcam capture means the material at risk is what a staffer was working on that week.
  • capability RUSTYMOVE gives the group a path onto hosts that never browsed a typosquatted page, including segmented or offline machines that web filtering was supposed to protect.
  • decision Defenders now have a schedule to hunt against: weekday-only GitHub calls in a fixed hour band, from systems with no reason to talk to a code host.

A private repository used as a dead drop puts the command channel inside TLS to github.com. RUSTYSHADE reads encrypted commands from specific files in the repo and sends data back the same way, including screenshots and webcam captures, according to Zscaler ThreatLabz [8]. Because the repositories are private, the stored commands are not readable without the account [3]. Detection built on newly registered domains, odd ports or DNS reputation does not fire on that traffic, and the destination host is one most organizations with developers allow by policy.

Domains do appear in this campaign, one stage earlier. ThreatLabz found typosquatted lookalikes of Indian news outlets, including The Print and India Today, hosting the malicious PowerShell scripts [7]. Proxy and DNS logs cover that stage, and blocklists and registrar monitoring work on it.

RUSTYMOVE skips the web stage. It is a Windows USB propagation tool, and it spreads RUSTYSHADE to other machines on removable drives [6][10]. A host that never loaded a fake India Today page can still end up with the backdoor. Government and defense targets tend to run segmented and offline networks, and those are the networks a USB carries the backdoor into.

The schedule is narrow. ThreatLabz observed the activity mainly between August 20 and September 1, 2026, and says C2 commands went out only on weekdays, within specific UTC hours [11][12]. A repeating weekday pattern of GitHub API requests from a server with no developer on it is something a hunt query can anchor to. August 20, 2026 was a Thursday and September 1 a Tuesday, so nine of the window's 13 days were weekdays [13].

Collection is selective. PSNATCH on Windows and BASHNATCH on Linux scan for and steal recently modified documents [4][5][9]. Two stealers for two operating systems means the group expects to land on both in the same target sets.

The four families are all new to public reporting. ThreatLabz describes the group as still evolving its toolkit and operating at high tempo [2][15]. The research is ThreatLabz's, summarized by SC Media, which cites The Hacker News [14]. The published account does not include a victim count or the repository names.

What to watch

  • Whether ThreatLabz or GitHub publishes the repository and account identifiers used for RUSTYSHADE C2. Blocking is not possible without them.
  • Whether BASHNATCH turns up outside Indian and Afghan government and defense targets.
  • Whether APT36 C2 activity continues past the September 1, 2026 end of the observed window, and on the same weekday UTC schedule.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories