As cited
Copy frozen at (site build).
threat intel
Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
In August 2026, Zscaler identified Operation RapidRust, a campaign by Pakistan-nexus APT36 targeting government and defense organizations in India and Afghanistan. The group deployed four new malware families: RUSTYSHADE, a Rust-based backdoor using GitHub repositories for command-and-control with AES-256-GCM encryption; RUSTYMOVE, a USB propagation tool for spreading malware to air-gapped networks; and PSNATCH and BASHNATCH, file-stealing tools for Windows and Linux that exfiltrate data to private GitHub repositories. Post-compromise activity between August 20 and September 1, 2026 included extensive reconnaissance, lateral movement attempts, and persistence mechanisms using scheduled tasks disguised as legitimate Microsoft services.
Why it matters: Government and defense organizations in India and Afghanistan face immediate risk from APT36's evolved tooling and active post-compromise operations; practitioners should monitor for typosquatted Indian news domains, private GitHub abuse for C2, and USB-based propagation attempts targeting air-gapped systems.
- Source published
- First seen by Cybersecurity Tracker