ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

Operation RapidRust: APT36's Rust Malware Suite Reaches Air-Gapped Indian and Afghan Government Networks

highThreat actorexploited in the wildimportance 78
What's new: New since the previous story summary (2026-09-17T09:49:47Z), based on the Cyber Security News report: (1) RUSTYMOVE polls removable devices every two seconds and drops payloads via disguised shortcuts, copying a fake-PDF shortcut and the RUSTYSHADE backdoor to removable media; (2) the OneDrive-impersonating persistence is now identified as the logon-triggered scheduled task…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Zscaler ThreatLabz details Operation RapidRust, an August 2026 campaign by Pakistan-aligned APT36 targeting Indian and Afghan government and defense organizations with four new tools — the RUSTYSHADE GitHub-C2 backdoor, the USB-spreading RUSTYMOVE, and the…

Zscaler ThreatLabz is tracking Operation RapidRust, an August 2026 campaign by Pakistan-aligned APT36 against Indian and Afghan government and defense organizations, introducing four new tools: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. RUSTYSHADE is a 64-bit Rust Windows backdoor that uses attacker-controlled private GitHub repositories as C2 with a hardcoded GitHub personal access token and AES-256-GCM-encrypted messages; it supports screenshot capture, webcam photos, directory listing, encrypted file download, and detached shell command execution, and is dropped via PowerShell from attacker-controlled Backblaze B2 storage. RUSTYMOVE is a removable-media propagation utility that spreads via USB, SD, MMC, and IEEE 1394 devices to bridge air-gapped networks, polls removable devices every two seconds, and drops payloads via disguised shortcuts that copy a fake-PDF shortcut and the RUSTYSHADE backdoor. PSNATCH is a PowerShell file stealer that scans Office documents, archives, media/images, and databases modified in the last 120 days, capped at 1 GB per file and 5 GB per run, exfiltrating via the GitHub API to per-machine repositories; GBHackers describes PSNATCH and BASHNATCH as Windows and Linux stealers collecting files from user folders and drives D: through H:, whereas Zscaler describes PSNATCH specifically as a PowerShell (Windows) tool. Payloads were staged on typosquat domains theprints[.]org and indiatodays[.]org spoofing ThePrint and India Today plus Backblaze B2 storage. Persistence used scheduled tasks impersonating OneDrive and Microsoft Edge updates, including a logon-triggered scheduled task, StandAloneOneDriveUpdater-2626, that launches the USB spreader. Operators ran C2 commands between 04:00 and 11:00 UTC and enumerated users, processes, shares, and remote administrative shares to expand beyond initial victims. The tooling resembles GITSHELLPAD from the earlier GOGITTER campaign but is rewritten in Rust with encrypted C2. IoCs include file hashes, lookalike domains such as indiatodays[.]org, and Backblaze staging URLs.

  • Operation RapidRust is an August 2026 campaign by Pakistan-aligned APT36 targeting Indian and Afghan government and defense organizations, per Zscaler ThreatLabz.
  • Four new tools deployed: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH.
  • RUSTYSHADE is a 64-bit Rust Windows backdoor using attacker-controlled private GitHub repositories as C2 with a hardcoded GitHub personal access token and AES-256-GCM-encrypted messages.
  • RUSTYSHADE supports screenshot capture, webcam photos, directory listing, encrypted file download, and detached shell command execution; it is dropped via PowerShell from attacker-controlled Backblaze B2 storage.
  • RUSTYMOVE spreads via USB, SD, MMC, and IEEE 1394 devices to bridge air-gapped networks, polling removable devices every two seconds and dropping payloads through disguised shortcuts that copy a fake-PDF shortcut and the RUSTYSHADE…
  • PSNATCH is a PowerShell file stealer scanning Office documents, archives, media/images, and databases modified in the last 120 days, capped at 1 GB per file and 5 GB per run, exfiltrated via the GitHub API to per-machine repositories.
  • GBHackers describes PSNATCH and BASHNATCH as Windows and Linux stealers collecting files from user folders and drives D: through H:; Zscaler describes PSNATCH as a PowerShell (Windows) tool.
  • Payload staging used typosquat domains theprints[.]org and indiatodays[.]org spoofing ThePrint and India Today, plus Backblaze B2 storage.

Coverage timeline

  1. · 21h ago
    Zscaler ThreatLabz· 70
    Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

    Zscaler details Operation RapidRust: APT36 deploys four new tools including RUSTYSHADE, a Rust backdoor using private GitHub repos for encrypted C2.

  2. · 2h ago
    GBHackers· 78
    APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal

    Pakistan-linked APT36 deployed a Rust malware suite, including RUSTYSHADE and USB-spreading RUSTYMOVE, against Indian and Afghan government and defense targets.

  3. · 2h ago
    Cyber Security News· 78
    APT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks

    Zscaler attributes the RapidRust campaign by Pakistan-linked APT36 to USB-propagating Rust malware targeting air-gapped government networks in India and Afghanistan.