CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7530

As cited

Copy frozen at (site build).

threat intel

Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

In August 2026, Zscaler identified Operation RapidRust, a campaign by Pakistan-nexus APT36 targeting government and defense organizations in India and Afghanistan. The group deployed four new malware families: RUSTYSHADE, a Rust-based backdoor using GitHub repositories for command-and-control with AES-256-GCM encryption; RUSTYMOVE, a USB propagation tool for spreading malware to air-gapped networks; and PSNATCH and BASHNATCH, file-stealing tools for Windows and Linux that exfiltrate data to private GitHub repositories. Post-compromise activity between August 20 and September 1, 2026 included extensive reconnaissance, lateral movement attempts, and persistence mechanisms using scheduled tasks disguised as legitimate Microsoft services.

Why it matters: Government and defense organizations in India and Afghanistan face immediate risk from APT36's evolved tooling and active post-compromise operations; practitioners should monitor for typosquatted Indian news domains, private GitHub abuse for C2, and USB-based propagation attempts targeting air-gapped systems.

VendorsMicrosoftAmazon Web ServicesGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary