At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | APT36 (also known as Transparent Tribe) |
| Activity Type | Cyber espionage, data exfiltration, lateral movement |
| Targets or Victims | Government and defense organizations in India and Afghanistan |
| Scale | Undisclosed number of infected systems and air-gapped networks |
| Jurisdiction / Status | Suspected Pakistan-nexus threat group |
| Source | Zscaler ThreatLabz |
Executive Summary
The Pakistan-nexus threat actor known as APT36 has launched a fresh wave of espionage attacks targeting government and defense sectors in India and Afghanistan. Dubbed Operation RapidRust, the campaign introduces a suite of newly developed tools written in Rust, PowerShell, and Bash to steal sensitive files. Security researchers discovered that the group relies heavily on cloud infrastructure, private GitHub repositories, and removable media to infiltrate isolated networks.
What Happened
In August 2026, threat researchers uncovered a new offensive campaign deploying custom malware against South Asian governments. The attackers registered typosquatted domains impersonating popular Indian news outlets, such as theprints[.]org and indiatodays[.]org, to stage malicious PowerShell scripts. Once a system is compromised, the attackers deploy the Operation RapidRust APT36 toolkit to harvest intelligence.
The primary payload is a 64-bit Windows backdoor written in Rust called RUSTYSHADE. This backdoor abuses attacker-controlled private GitHub repositories to facilitate command-and-control communications. According to Zscaler ThreatLabz, “All messages exchanged between RUSTYSHADE and the GitHub repositories are encrypted using AES-256-GCM.” The malware polls the GitHub API to retrieve commands from a specific text file and uploads the encrypted results to a separate text file.
To secure their data, RUSTYSHADE derives its encryption key from a cryptographic hash of a hard-coded GitHub personal access token. The malware generates a random 12-byte nonce using native Windows programming interfaces and encrypts the plaintext. It then formats the encrypted data with a specific prefix before applying Base64 encoding. This complex process ensures that security appliances cannot easily inspect the stolen data leaving the network.
Furthermore, the attackers deploy specialized file-stealing scripts known as PSNATCH and BASHNATCH for Windows and Linux environments, respectively. These tools recursively scan pre-configured directories, including OneDrive and external drives, for documents, archives, and databases modified within the last 120 days. They then exfiltrate the collected data directly to private GitHub repositories assigned specifically to each victim. The script limits collection to one gigabyte per file and five gigabytes per execution, allowing incremental exfiltration across repeated runs.
Who Is Behind It
Security experts attribute this campaign to APT36 with high confidence. Also known as Transparent Tribe, this suspected Pakistan-aligned espionage group has a long history of targeting Indian government, military, and diplomatic entities. The group typically focuses on intelligence collection and network reconnaissance.
Zscaler ThreatLabz noted the group’s relentless activity since earlier this year. In their report, researchers stated, “APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan.” By shifting their malware development toward Rust and utilizing cloud-backed command structures, the Operation RapidRust APT36 malware campaign highlights the group’s evolving technical capabilities.
Impact and Scale
The campaign poses a severe risk to secure government infrastructure due to its ability to bridge segmented networks. To reach systems without direct internet access, APT36 utilizes a lightweight USB propagation tool named RUSTYMOVE. This tool monitors infected hosts for external removable media, such as USB thumb drives or SD cards. When it detects a new drive, it copies a malicious archive containing the RUSTYSHADE executable to the root directory, enabling the malware to spread to air-gapped networks.

During post-compromise activity, the operators performed sweeping network reconnaissance. They mapped local networks, resolved hostnames, and enumerated visible SMB shares to identify potential lateral movement targets. Attackers also scheduled tasks that masqueraded as legitimate Microsoft Edge or OneDrive updaters to ensure persistence on the infected machines. Interestingly, operational analysis showed that the attackers only issued commands on weekdays between 4:00 a.m. and 11:00 a.m. UTC. This strict timing pattern suggests a structured operation run by dedicated personnel operating during standard shifts.
What Comes Next
The increasing use of commercial cloud services for remote administration complicates detection efforts. Because the attackers rely on custom malware and encrypted GitHub API channels, standard antivirus signatures may not provide adequate protection. Network defenders should carefully monitor endpoints for unauthorized PowerShell executions and unusual web requests directed at developer platforms.
To stay protected, agencies must enforce strict policies restricting the use of unauthorized USB devices. Enhanced network segmentation and regular auditing of scheduled tasks will also help limit unauthorized lateral movement.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!