Executive Summary

In September 2026, the Pakistan-aligned threat group Transparent Tribe (APT36) launched Operation RapidRust, targeting government and defense entities in India and Afghanistan with four new malware families: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The campaign utilized innovative command-and-control infrastructure through private GitHub repositories and typosquatted domains mimicking Indian news organizations. The sophisticated attack chain involved a Rust-based backdoor for encrypted communications, USB propagation tools, and cross-platform file stealers capable of exfiltrating up to 5GB of sensitive data per execution.

This incident highlights the evolving threat landscape where nation-state actors increasingly leverage legitimate cloud services for malicious infrastructure while expanding their technical capabilities across multiple operating systems and attack vectors.

Why This Matters Now

Nation-state groups are increasingly weaponizing legitimate cloud platforms like GitHub for command-and-control, making detection more challenging and demonstrating the urgent need for enhanced monitoring of authorized services and cross-platform security controls.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

RUSTYSHADE communicates through private GitHub repositories using the GitHub REST API, storing encrypted commands and results in specific files like command.txt and results.txt for bidirectional communication.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain APT36's multi-stage attack by limiting lateral movement between systems and reducing outbound communication paths. The segmented architecture could significantly reduce the blast radius of this espionage campaign targeting government and defense entities.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native security controls would likely reduce the initial foothold scope by constraining workload communications and limiting the backdoor's ability to establish broad network access across cloud environments.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely constrain reconnaissance activities and limit privilege escalation scope by restricting cross-system access and reducing the backdoor's ability to discover additional network resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely limit the effectiveness of USB-based lateral movement by constraining inter-workload communications and reducing the malware's ability to spread across segmented network zones.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility controls would likely detect and constrain unauthorized GitHub API communications, reducing the backdoor's command and control reliability across multiple cloud environments and network segments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely constrain data exfiltration volume and frequency by limiting outbound GitHub repository access and reducing the file stealers' ability to transfer sensitive documents externally.

Impact (Mitigations)

While some sensitive document exposure may still occur, the overall espionage impact would likely be significantly reduced through constrained lateral access and limited data exfiltration pathways.

Impact at a Glance

Affected Business Functions

  • National Defense Operations
  • Government Administrative Services
  • Intelligence and Security Communications
  • Critical Infrastructure Coordination
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Government and defense-related sensitive documents including Microsoft Office files, images, archives, and databases. System reconnaissance data, desktop screenshots, and webcam captures were exfiltrated. The campaign targeted high-value intelligence from government entities in India and Afghanistan, with file collection limited to 1GB per file and 5GB per execution.

Recommended Actions

  • Implement egress security and policy enforcement to block unauthorized outbound connections to suspicious GitHub repositories and typosquatted domains
  • Deploy zero trust segmentation with least privilege access controls to prevent USB-based lateral movement between network segments
  • Enable multicloud visibility and control to detect anomalous GitHub API traffic patterns during specific time windows (4-11 AM UTC weekdays)
  • Establish threat detection and anomaly response capabilities to identify file stealer activities targeting Office documents and sensitive data repositories
  • Implement encrypted traffic inspection (HPE) to detect and prevent data exfiltration through encrypted channels including GitHub repository uploads

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image