The South Asian espionage group known as APT36 has overhauled its offensive toolset in Rust, routing covert command-and-control through private GitHub repositories while weaponizing USB thumb drives to cross physical network air gaps.
Operation RapidRust: Multi-Tier Campaign Architecture
Typosquatted News Outlets
indiatodays[.]org
- Phishing lures mimicking scanned PDFs
- Masqueraded Windows shortcut files (
.LNK) - Secondary payloads staged on Backblaze B2
Private GitHub Repositories
- Inbound commands pulled via
command.txt - Results uploaded via
results.txt - Encrypted desktop snapshots & webcams
Compiled Implants & Stealers
- RUSTYSHADE: Resident reconnaissance backdoor
- RUSTYMOVE: Wormable USB propagator
- PSNATCH / BASHNATCH: 90-day document stealers
Executive Summary
For years, state-sponsored cyber espionage campaigns followed a predictable network signature. Operators would spin up cheap virtual private servers, compromise unpatched WordPress sites, or register dynamic DNS records to receive stolen data. But modern network defenses have caught up. Security Operations Centers (SOCs) now routinely flag anomalous outbound connections to unfamiliar IP spaces within minutes.
Adversaries have adjusted by moving their infrastructure into trusted enterprise software-as-a-service ecosystems. In late August 2026, security researchers discovered an espionage campaign tracked as Operation RapidRust, orchestrated by the Pakistan-aligned threat group Transparent Tribe (also cataloged as APT36 and Earth Karkaddan) under MITRE ATT&CK entry G0056[4]. Documented in a detailed threat advisory published by Zscaler ThreatLabz[1], the intrusion wave singled out military, defense, and diplomatic targets across India and Afghanistan.
What sets Operation RapidRust apart is not just its geopolitical focus, but its complete engineering overhaul. Transparent Tribe has discarded its brittle Visual Basic scripts and bloated .NET binaries in favor of high-performance implants compiled in Rust. The primary payload, named RUSTYSHADE, establishes a stealthy dead-drop command channel using private GitHub repositories over HTTPS. Working alongside RUSTYSHADE is RUSTYMOVE, a companion utility designed to jump across physical air gaps via USB flash drives, and two twin file-harvesting scripts — PSNATCH and BASHNATCH — tailored for Windows and Linux endpoints.
Adversary Context: The Maturation of APT36
Transparent Tribe has operated in the shadows of South Asian geopolitics for well over a decade according to historical ATT&CK intelligence[4]. In its early years, the group earned a reputation for being persistent but technically unsophisticated. Their playbook relied heavily on off-the-shelf remote access trojans such as Crimson RAT, macro-laden Microsoft Office documents, and basic credential harvesting lures circulated across WhatsApp and spear-phishing emails.
Treating Transparent Tribe as a low-tier operator today is a mistake. Over the past two years, the group has systematically rebuilt its development pipeline. They have moved steadily away from interpreted languages toward modern, compiled cross-platform languages including Go and Rust. Only weeks before the emergence of RapidRust, independent researchers tracked the group deploying a bespoke implant called PATCHCORD against critical telecommunications infrastructure in South Asia as reported by cybersecurity journalists[2].
Operation RapidRust is the clearest proof yet of this engineering evolution. Rust provides threat actors with significant operational advantages: deterministic memory safety eliminates unexpected runtime crashes, native compilation enables direct Windows API interactions without external runtime dependencies, and the resulting complex machine code creates a maze of symbols and control flows that severely complicates static reverse-engineering and legacy YARA signature matching.
Initial Access: Typosquatting Indian News Media
The intrusion pipeline begins with deceptive social engineering that exploits regional media consumption habits. APT36 registered lookalike domain names impersonating legitimate, high-circulation Indian news organizations:
theprints[.]org— engineered to impersonate digital news portal ThePrint (legitimate:theprint.in)indiatodays[.]org— registered to spoof national publication India Today (legitimate:indiatoday.in)
These typosquatted domains acted as staging hubs hosting malicious PowerShell loaders detailed in Zscaler's campaign telemetry[1]. Targets received spear-phishing messages carrying ZIP archives containing weaponized Windows shortcut files designed to look like routine administrative or military scans, including files labeled DocScanner-11-Aug-2026-5-37pm.pdf.LNK as confirmed by file metadata audits[2].
Once executed, the shortcut silently triggered a background PowerShell command that pulled secondary binaries from Backblaze B2 cloud storage cataloged in defensive threat advisories[3]. By routing download requests through a major cloud storage vendor, the initial payload delivery generated zero reputation-based alerts in corporate web proxies.
Technical Breakdown: The RUSTYSHADE GitHub C2 Backdoor
Once deposited on an endpoint, the main backdoor — RUSTYSHADE — initiates execution. RUSTYSHADE is a 64-bit Windows implant compiled in Rust that borrows structural logic from GITSHELLPAD, a Golang tool used by Transparent Tribe in its late-2025 "Gopher Strike" operations according to retrospective incident data[2].
Instead of establishing a persistent TCP socket or opening an interactive web shell to an attacker-owned IP address, RUSTYSHADE operates as a dead-drop client communicating entirely with the official GitHub REST API (api.github.com). It accesses private repositories provisioned by the threat actor, using personal access tokens embedded within the malware or delivered dynamically.
RUSTYSHADE GitHub Repository Synchronization Matrix
Bidirectional encrypted file transfers executed entirely over HTTPS (Port 443) to api.github.com.
| Repository File | Direction | HTTP Action | Operational Function |
|---|---|---|---|
| command.txt | Inbound | GET | Operator pushes encrypted commands for host execution. |
| results.txt | Outbound | PUT | Returns encrypted execution logs, stdout, and error streams. |
| info.txt | Outbound | PUT | Transmits host reconnaissance: OS build, username, GUID, and IP. |
| heartbeat.txt | Outbound | PUT | Periodic timestamps confirming the implant remains operational. |
| screenshot.png | Outbound | PUT | Encrypted desktop captures uploaded on operator instruction. |
| webcam_photo.jpg | Outbound | PUT | Encrypted snapshots extracted from attached webcam peripherals. |
| download.bin | Outbound | PUT | Staged document bundles exfiltrated directly by RUSTYSHADE. |
The technical brilliance of this approach lies in its network profile. Automated perimeter firewalls and security gateways see encrypted traffic addressed to Microsoft-owned IP ranges, accompanied by valid TLS certificates. To an intrusion detection system, the activity appears identical to a developer committing code or running CI/CD automation tasks as highlighted by ThreatLabz researchers[1].
Crossing Physical Air Gaps: RUSTYMOVE
In defense ministries and military headquarters across India, high-security workstations are routinely air-gapped — completely isolated from the public internet. Threat actors focused on espionage must have a mechanism to reach these isolated networks. Transparent Tribe solved this problem with RUSTYMOVE.
Compiled as a 64-bit Rust binary, RUSTYMOVE is a dedicated removable media weaponization utility identified in Zscaler's reverse engineering report[1]. Rather than exploiting hardware flaws in the USB controller stack, RUSTYMOVE executes a continuous background polling script querying the Windows Management Instrumentation (WMI) interface for logical drive changes.
RUSTYMOVE Removable Media Weaponization Pipeline
RUSTYMOVE runs a continuous background PowerShell polling loop to immediately detect when an external USB storage drive mounts on the system.
The utility silently drops a ZIP archive containing the RUSTYSHADE executable alongside a masqueraded PDF shortcut file directly onto the root of the thumb drive.
When plugged into a non-networked workstation, user interaction triggers the fake PDF shortcut, which automatically unzips the archive and launches RUSTYSHADE locally.
The process requires zero zero-day exploits. The moment a USB flash drive connects to an infected, internet-facing PC, RUSTYMOVE writes two files to the root volume:
DriverInstaller.zip— A compressed archive containing the full RUSTYSHADE binary.DocScanner-11-Aug-2026-5-37pm.pdf.LNK— A Windows shortcut that uses a default Adobe Acrobat icon to disguise its true nature as observed during technical dissections[2].
When an officer or government contractor carries that thumb drive into a secure, air-gapped facility and double-clicks the deceptive shortcut, Windows unzips the archive and executes RUSTYSHADE silently in the background. While the air-gapped system cannot reach GitHub immediately, secondary tools harvest local documents and save them back onto the USB drive, waiting for the drive to be reconnected to an internet-facing workstation.
Dual-Platform Harvesting: PSNATCH (Windows) & BASHNATCH (Linux)
Espionage operations ultimately exist to extract sensitive documents. Once RUSTYSHADE verifies host access, the operators deploy secondary file stealers hosted on an attacker-controlled GitHub gist. These stealers exist in two parallel versions: PSNATCH for Windows and BASHNATCH for Linux distributions.
PSNATCH (Windows) vs. BASHNATCH (Linux)
- Strict 90-day creation/modification recency filter
- Collects DOCX, XLSX, PPTX, PDF, media, and keys
- Individual file size ceiling: 1 GB
- Execution cycle quota: 5 GB per run
- Scans
/home,/root,/etc, and mounted media - Collects configs, archives (.tar, .gz), and shell scripts
- Dynamically auto-provisions private GitHub repos
- Names repository after the compromised host
Both scripts display remarkable operational discipline. Rather than recklessly scraping entire hard drives — an action guaranteed to saturate network interfaces and trigger endpoint detection and response (EDR) alerts — the stealers apply strict filtering rules:
- 90-Day Recency Gate: The stealers evaluate filesystem metadata, ignoring any file created or modified more than 90 days (three months) prior as confirmed by reverse-engineering teardowns[2]. This ensures only fresh, operationally relevant intelligence is exfiltrated.
- Targeted Extensions: Scans hone in on administrative documents (Office files, PDFs), database exports, cryptographic keys, network configs, and compressed archives.
- Bandwidth Safeguards: PSNATCH enforces an individual file limit of 1 GB and caps total exfiltration at 5 GB per run documented in Zscaler's technical report[1].
- Deduplication via SmartUploader: To avoid repeatedly uploading the same data across scheduled executions, the malware logs every exfiltrated file into a JSON file:
- Windows:
%APPDATA%\SmartUploader\uploaded_files.jsoncataloged in endpoint forensics[3] - Linux:
~/.local/share/SmartUploader/uploaded_files.jsonreferenced in Linux hunting telemetry[3]
- Windows:
Harvested files are organized into dedicated GitHub repositories named after the compromised host's machine name, providing the operators with a cleanly indexed, cloud-hosted intelligence repository for every victim.
Operational Footprint: The 9-to-5 Nation-State Workday
Popular culture often imagines state-sponsored hackers working at odd hours in dark basements. The telemetry from Operation RapidRust tells a much different, more bureaucratic story.
During the active surveillance window between August 20 and September 1, 2026, researchers tracked the exact timestamps of commits made to command.txt across victim repositories recorded by Zscaler ThreatLabz[1]. Operational activity followed an unyielding schedule:
Observed Threat Operator Hours:
04:00 UTC to 11:00 UTC — Monday through Friday only
When converted to Pakistan Standard Time (PKT, UTC+5), this window corresponds precisely to 09:00 AM to 04:00 PM. The operators work standard government office hours. C2 tasks cease during weekends and regional holidays. For threat intelligence analysts, this temporal fingerprint provides compelling operational corroboration of institutional, state-backed employment structures.
Defensive Implications: Hunting Legitimate Web Service Abuse
Operation RapidRust underscores a hard truth for defensive security teams: domain reputation alone is dead. Blocking "known bad" IP addresses does nothing to protect an organization when attackers manage their intrusions through GitHub, Backblaze, and AWS.
Defending against campaigns like RapidRust requires pivoting from static perimeter blocking to behavioral, host-centric anomaly detection.
1. Behavioral GitHub API Telemetry
Developer workstations communicate with GitHub daily, but administrative computers, military command terminals, and human resources endpoints almost never need to connect to api.github.com. Security teams should audit endpoint network telemetry, flagging any non-development process (such as standalone Rust binaries or PowerShell) making periodic HTTPS calls to GitHub REST endpoints as advised in proactive hunting advisories[3].
2. Endpoint Forensic Artifacts
SOC analysts can immediately search fleet endpoints for specific artifacts unique to the RapidRust toolchain:
- Presence of tracking files:
*\SmartUploader\uploaded_files.jsonhighlighted in detection advisories[3] - Creation of
DriverInstaller.zipor deceptive.LNKshortcut files in the root directory of removable USB volumes (drive types 2 and 3) - Reconnaissance commands executed via unmanaged command prompts:
net view,net share,nbtstat, andTest-NetConnection
3. Strict Removable Media Governance
Because RUSTYMOVE relies on human-facilitated USB transfer to cross network boundaries, hardware access controls provide a foolproof defensive barrier. Enforcing USB mass storage restrictions via Group Policy or endpoint agents — or requiring hardware-encrypted, approved drives — prevents RUSTYMOVE from establishing a foothold in classified environments.
Security Takeaway
Transparent Tribe's transition to Rust and GitHub-based command-and-control marks a permanent shift in how regional adversaries conduct cyber espionage. By embedding within legitimate developer services, automating air-gap traversal via thumb drives, and establishing disciplined data collection quotas, APT36 has built an operational model designed to survive within well-defended enterprise networks.
For cybersecurity leaders, the lesson is clear: trusting the destination domain is not the same as trusting the traffic. When adversaries turn enterprise collaboration platforms into espionage infrastructure, detection hinges on recognizing behavioral anomalies on the endpoint, enforcing strict device boundaries, and monitoring authenticated cloud API interactions.

Technical Discussion & Feedback
Leave a Comment (Authenticated Users)