Executive Summary
In September 2026, the Pakistan-aligned threat group Transparent Tribe (APT36) launched Operation RapidRust, targeting government and defense entities in India and Afghanistan with four new malware families: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The campaign utilized innovative command-and-control infrastructure through private GitHub repositories and typosquatted domains mimicking Indian news organizations. The sophisticated attack chain involved a Rust-based backdoor for encrypted communications, USB propagation tools, and cross-platform file stealers capable of exfiltrating up to 5GB of sensitive data per execution.
This incident highlights the evolving threat landscape where nation-state actors increasingly leverage legitimate cloud services for malicious infrastructure while expanding their technical capabilities across multiple operating systems and attack vectors.
Why This Matters Now
Nation-state groups are increasingly weaponizing legitimate cloud platforms like GitHub for command-and-control, making detection more challenging and demonstrating the urgent need for enhanced monitoring of authorized services and cross-platform security controls.
Attack Path Analysis
Transparent Tribe (APT36) compromised government and defense entities in India and Afghanistan through typosquatted domains hosting malicious PowerShell scripts. The attackers deployed RUSTYSHADE Rust backdoor for C2 via private GitHub repositories, used RUSTYMOVE for USB propagation to achieve lateral movement, maintained persistence through encrypted GitHub API communications, and exfiltrated sensitive documents using PSNATCH and BASHNATCH file stealers with 5GB execution limits.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
APT36 registered typosquatted domains (theprints[.]org, indiatodays[.]org) impersonating Indian news organizations to host malicious PowerShell scripts and deliver RUSTYSHADE backdoor to government and defense targets
MITRE ATT&CK® Techniques
Spearphishing Attachment
PowerShell
Dead Drop Resolver
Archive via Utility
Exfiltration Over C2 Channel
Replication Through Removable Media
Screen Capture
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
CISA Zero Trust Maturity Model 2.0 – Data Loss Prevention
Control ID: DA.L2
DORA – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Information Deletion
Control ID: A.8.10
SOC 2 Type II – Logical and Physical Access Controls
Control ID: CC6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct target of APT36 cyber espionage campaign using RUSTYSHADE backdoor, requiring enhanced encrypted traffic monitoring and zero trust segmentation to prevent lateral movement within government networks.
Defense/Space
Primary target alongside government entities, vulnerable to Rust-based backdoors and USB propagation tools, necessitating strengthened egress security and multicloud visibility for classified defense systems.
Telecommunications
Previously targeted by same threat actor using PATCHCORD backdoor, faces ongoing risks from GitHub-based C2 communications requiring enhanced threat detection and anomaly response capabilities.
Information Technology/IT
Critical infrastructure supporting targeted sectors, must implement Kubernetes security and cloud firewall protections against sophisticated multi-platform file stealers and lateral movement tools like RUSTYMOVE.
Sources
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.htmlVerified
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCHhttps://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-andVerified
- New PATCHCORD Backdoor Targets Afghan Telecom Providershttps://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.htmlVerified
- Pakistan-Linked Cyber Espionage Campaign Gopher Strikehttps://thehackernews.com/2026/01/experts-detect-pakistan-linked-cyber.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain APT36's multi-stage attack by limiting lateral movement between systems and reducing outbound communication paths. The segmented architecture could significantly reduce the blast radius of this espionage campaign targeting government and defense entities.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security controls would likely reduce the initial foothold scope by constraining workload communications and limiting the backdoor's ability to establish broad network access across cloud environments.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely constrain reconnaissance activities and limit privilege escalation scope by restricting cross-system access and reducing the backdoor's ability to discover additional network resources.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely limit the effectiveness of USB-based lateral movement by constraining inter-workload communications and reducing the malware's ability to spread across segmented network zones.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility controls would likely detect and constrain unauthorized GitHub API communications, reducing the backdoor's command and control reliability across multiple cloud environments and network segments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain data exfiltration volume and frequency by limiting outbound GitHub repository access and reducing the file stealers' ability to transfer sensitive documents externally.
While some sensitive document exposure may still occur, the overall espionage impact would likely be significantly reduced through constrained lateral access and limited data exfiltration pathways.
Impact at a Glance
Affected Business Functions
- National Defense Operations
- Government Administrative Services
- Intelligence and Security Communications
- Critical Infrastructure Coordination
Estimated downtime: 7 days
Estimated loss: N/A
Government and defense-related sensitive documents including Microsoft Office files, images, archives, and databases. System reconnaissance data, desktop screenshots, and webcam captures were exfiltrated. The campaign targeted high-value intelligence from government entities in India and Afghanistan, with file collection limited to 1GB per file and 5GB per execution.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security and policy enforcement to block unauthorized outbound connections to suspicious GitHub repositories and typosquatted domains
- • Deploy zero trust segmentation with least privilege access controls to prevent USB-based lateral movement between network segments
- • Enable multicloud visibility and control to detect anomalous GitHub API traffic patterns during specific time windows (4-11 AM UTC weekdays)
- • Establish threat detection and anomaly response capabilities to identify file stealer activities targeting Office documents and sensitive data repositories
- • Implement encrypted traffic inspection (HPE) to detect and prevent data exfiltration through encrypted channels including GitHub repository uploads



