securityonline.info 22 Sept 2026, 07:10 UTC

APT36 Uses Fake Indian News Sites to Deploy Rust Backdoor Against India, Afghanistan

APT36 Uses Fake Indian News Sites to Deploy Rust Backdoor Against India, Afghanistan
CyberSIXT Evidence Panel
Threat Actor

ZSCALER ThreatLabz has reported a campaign dubbed Operation RapidRust, attributed with high confidence to APT36, also known as Transparent Tribe, a suspected Pakistan-nexus espionage group. The activity targets government and defence organisations in India and Afghanistan. Researchers say the campaign, uncovered in August 2026, uses typosquatted domains impersonating Indian news outlets, including theprints[.]org and indiatodays[.]org, to deliver malicious PowerShell scripts.

The main payload is RUSTYSHADE, a 64-bit Windows backdoor written in Rust. It uses private GitHub repositories for encrypted command-and-control: commands are retrieved through the GitHub API and results are uploaded to separate repository files using AES-256-GCM. PSNATCH and BASHNATCH scripts target Windows and Linux systems, scanning locations such as OneDrive and removable drives for documents, archives and databases changed within the previous 120 days. Collection is limited to 1GB per file and 5GB per run, supporting repeated exfiltration.

The campaign also includes RUSTYMOVE, which copies a malicious archive to newly connected USB drives or SD cards, potentially enabling transfer into air-gapped networks. Threat researchers observed network reconnaissance, SMB-share enumeration and scheduled tasks disguised as Microsoft Edge or OneDrive updates. Commands were issued only on weekdays between 04:00 and 11:00 UTC.

The report recommends monitoring unauthorised PowerShell and unusual requests to developer platforms, restricting removable media, improving segmentation and auditing scheduled tasks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline