{"id":2977,"date":"2026-09-18T16:40:39","date_gmt":"2026-09-18T16:40:39","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2977"},"modified":"2026-09-18T16:40:39","modified_gmt":"2026-09-18T16:40:39","slug":"transparent-tribe-deploys-new-rust-backdoor-using-private-github-repositories-for-c2","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2977","title":{"rendered":"Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 18, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Cyber Espionage<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjhBM0nXgCLpwEyXmAdxLO_GatYww1Cem0yuGGqhmMwCB5N8w-TeoMm7jV4SbH4hjfYmxctUjyPiSlR3Caj2cSu7L_1nxTzg5xtfJrxhq5y0elL7yh8J2S5lakpnTbck3XhMVB1iG3obibSh64E8z877YcECkeJBs_rrZARXefKDeYQJ9Nf2u8pnxD0gEnx\/s1700-nu-rw-lo-l85-e365\/rust-malware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.<\/p>\n<p>The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed <strong>Operation RapidRust<\/strong>.<\/p>\n<p>\u00abAPT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan,\u00bb <a href=\"https:\/\/sudeepvision.com\/\" target=\"_blank\">Sudeep Singh<\/a>, senior manager of APT Research at Zscaler ThreatLabz, <a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and\" target=\"_blank\">said<\/a> in a technical report published this week.<\/p>\n<p>The discovery comes a little over a month after  Acronis Threat Research Unit (TRU) tied the long-running persistent threat group to another campaign aimed at Afghan telecom providers and South Asian critical infrastructure organizations using a backdoor called PATCHCORD.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>A notable aspect of the campaign is the threat actor&#8217;s use of private GitHub repositories for command-and-control (C2) and the registration of typosquatted domains impersonating popular Indian news organizations like The Print and India Today to host malicious PowerShell scripts and payloads &#8211;<\/p>\n<ul>\n<li>theprints[.]org, which mimics The Print (\u00abtheprint[.]in\u00bb)<\/li>\n<li>indiatodays[.]org, which mimics India Today (\u00abindiatoday[.]in\u00bb)<\/li>\n<\/ul>\n<p>Among the four newly identified malware families, one is a backdoor, another is a lateral movement utility, while the remaining two are file-stealing programs designed for Windows and Linux systems.<\/p>\n<p>RUSTYSHADE, as the name implies, is a Rust-based backdoor that makes use of attacker-controlled private GitHub repositories for encrypted C2 communications. It shares some level of functionality overlap with <a href=\"https:\/\/thehackernews.com\/2026\/01\/experts-detect-pakistan-linked-cyber.html\" target=\"_blank\">GITSHELLPAD, a Golang implant that was observed in September 2025 in connection with a campaign known as Gopher Strike.<\/p>\n<p>Specifically, the malware parses and writes certain files in the private GitHub repository for bidirectional communication using the GitHub REST API. The names of the files are below &#8211;<\/p>\n<ul>\n<li>command.txt, for storing encrypted C2 commands<\/li>\n<li>results.txt, for storing encrypted command output<\/li>\n<li>info.txt, to store system reconnaissance data<\/li>\n<li>heartbeat.txt, for keepalive beaconing to confirm active infection<\/li>\n<li>screenshot.png, for encrypted desktop screenshot<\/li>\n<li>webcam_photo.jpg, for encrypted webcam capture<\/li>\n<li>download.bin, for encrypted exfiltrated file contents<\/li>\n<\/ul>\n<p>The commands allow RUSTYSHADE to take screenshots, capture a webcam photo, perform file operations, and run commands in the background.<\/p>\n<p>As part of post-compromise activity, the threat actor has been observed fetching a file stealer from an attacker-controlled GitHub gist that comes in two variants for targeting both Windows and Linux environments &#8211;<\/p>\n<ul>\n<li>PSNATCH, a PowerShell stealer that recursively scans preconfigured directories for Microsoft Office documents, images, archives, media, executables, scripts, and databases that were modified within the last three months and exfiltrates them to a private repository named after the infected machine. The file collection is limited to 1 GB per file and 5 GB per execution.<\/li>\n<li>BASHNATCH, a bash script similar to PSNATCH that targets Linux systems<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Perhaps the most interesting of the lot is RUSTYMOVE, a lightweight 64-bit Windows USB propagation tool developed in Rust. Its main responsibility is to continuously monitor for external removable media using a PowerShell script and copy two pre-staged malicious files to the root directory of each detected external drive &#8211;<\/p>\n<ul>\n<li>DriverInstaller.zip, which contains RUSTYSHADE<\/li>\n<li>DocScanner-11-Aug-2026-5-37pm.pdf.LNK, which is suspected to contain a command to execute RUSTYSHADE after extraction<\/li>\n<\/ul>\n<p>Post-compromise activity from APT36 operators involves system, user, and network reconnaissance, followed by the deployment of next-stage payloads. A significant portion of the actions took place between August 20 and September 1, 2026, with the C2 commands issued only between 4 a.m. and 11 a.m. UTC and only on weekdays.<\/p>\n<p>\u00abThis campaign demonstrates that APT36 continues to target government and defense entities in India and Afghanistan while maintaining high operational tempo and evolving TTPs,\u00bb Singh said.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 18, 2026Malware \/ Cyber Espionage The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2978,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[179,297,71,986,1738,574,499,500],"class_list":["post-2977","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoor","tag-deploys","tag-github","tag-private","tag-repositories","tag-rust","tag-transparent","tag-tribe"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2977","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2977"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2977\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2978"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2977"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2977"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2977"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}