On the morning of 18 September 2026, Zscaler ThreatLabz published its analysis of Operation RapidRust—a fresh offensive campaign by APT36 (Transparent Tribe), the Pakistan state-sponsored threat group that has been targeting India since at least 2013. The new tool-set is a significant upgrade: four previously undocumented malware families, two of them written in Rust, with command-and-control traffic hidden inside private GitHub repositories. For every IT leader running networks that touch India’s public sector, defence supply chain, or government-adjacent services, this is an active threat that demands immediate attention.

Key Takeaways

  • APT36 (Transparent Tribe), a Pakistan-nexus nation-state group, launched Operation RapidRust targeting Indian and Afghan government and defence organisations.
  • Four new malware families confirmed: RUSTYSHADE (Rust backdoor), RUSTYMOVE (USB propagation), PSNATCH (Windows file stealer), BASHNATCH (Linux file stealer).
  • RUSTYSHADE uses private GitHub repos as encrypted C2—traffic blends with normal developer activity and evades many proxy-based controls.
  • RUSTYMOVE is designed to jump air-gapped networks by staging payloads on removable media.
  • Operators work Monday–Friday, 04:00–11:00 UTC (09:30–16:30 IST)—highly organised, persistent, and well-funded.
  • Malicious infrastructure masquerades as Indian news outlets: theprints[.]org and indiatodays[.]org.
  • No specific CVE—the campaign relies on spear-phishing and social engineering, making people the first control.

Why Operation RapidRust Is a Turning Point for APT36

APT36 is not new. The group—also tracked as Earth Karkadann, ProjectM, and Mythic Leopard—has historically relied on commodity remote access tools such as CrimsonRAT and ElizaRAT, phishing lures disguised as government advisories, and simple Python-based stagers. What makes Operation RapidRust significant is the deliberate shift to Rust, a systems programming language that produces binaries with minimal standard-library signatures, making detection by AV and EDR considerably harder.

The choice of private GitHub repositories as a command-and-control channel is equally sophisticated. GitHub traffic is encrypted TLS, originates from a trusted CDN, and is allowed through corporate firewalls in almost every Indian enterprise and government network. A well-configured Next-Generation Firewall can inspect TLS—but only if it is configured to do so. A misconfigured or over-permissive FortiGate policy that bypasses TLS inspection for github.com will pass RUSTYSHADE C2 traffic silently.

The campaign was active 20 August – 1 September 2026 with Zscaler confirming artefacts and telemetry; the report was published publicly on 18 September 2026. There is no indication the campaign has stopped.

Technical Breakdown: Four New Tools in the APT36 Arsenal

Zscaler ThreatLabz reverse-engineered all four families. Here is what each component does:

Malware Platform Primary Role Key Evasion
RUSTYSHADE Windows 64-bit Full-featured backdoor, screenshots, webcam, file exfiltration Rust binary; GitHub private repo C2; AES-256-GCM
RUSTYMOVE Windows 64-bit Removable-media propagation, air-gap traversal Scheduled task named StandAloneOneDriveUpdater-2626
PSNATCH Windows (PowerShell) Document stealer — Office, PDFs, archives, databases SmartUploader user-agent; incremental JSON tracking
BASHNATCH Linux (Bash) Linux equivalent of PSNATCH Mirrors PSNATCH logic; targets ~/.local/share/

RUSTYSHADE is the crown jewel. Once installed, it polls a private GitHub repository using a hardcoded Personal Access Token (PAT). Commands are fetched from command.txt, encrypted with AES-256-GCM and a SHA-256-derived key. Results are written to results.txt. The message format—HCENC1:[base64(nonce || ciphertext || tag)]—is compact and indistinguishable from normal GitHub API traffic at the packet level.

RUSTYMOVE is designed for the one scenario that defeats most perimeter controls: the trusted employee with a USB drive. The tool monitors removable media and copies two files—DriverInstaller.zip (containing RUSTYSHADE) and a malicious LNK file—to every inserted USB. When the target’s colleague plugs that drive into an air-gapped workstation in a secure government facility, the payload executes automatically at logon via a scheduled task disguised as a OneDrive updater.

PSNATCH targets documents modified within the last 120 days on Desktop, Downloads, Documents, OneDrive folders, and drives D through H. It uploads findings to Backblaze S3 buckets using incremental tracking so that only new files are sent on repeat runs—a sign of careful operational tradecraft.

The Infrastructure: Hiding in Legitimate Services

APT36’s choice of infrastructure in Operation RapidRust is deliberately anti-forensic. Command traffic flows through GitHub’s API—a service that most network monitoring tools treat as trusted. Payload staging uses Backblaze B2 cloud storage. Phishing lures are delivered from typosquatted Indian media domains registered on NameCheap:

  • theprints[.]org — impersonates theprint.in, a widely-read Indian political and policy publication (registered May 11, 2026)
  • indiatodays[.]org — impersonates indiatoday.in, India’s largest English news network (registered Aug 17, 2026)

These domains are recent—indiatodays[.]org was registered just days before the observed campaign activity. The spear-phishing emails carrying these lures would look highly credible to any government official who regularly reads Indian news. The urgency of adding these domains to your DNS blacklist right now cannot be overstated.

C2 hours—04:00 to 11:00 UTC, Monday through Friday only—map to Indian Standard Time 09:30 to 16:30 IST. Threat operators are working standard office hours from Pakistan, which gives defenders a specific window to monitor outbound GitHub API traffic for anomalies.

Indicators of Compromise

Block and hunt for the following confirmed IoCs from the Zscaler ThreatLabz report:

Type Value Associated Malware
Domain theprints[.]org RUSTYSHADE delivery
Domain indiatodays[.]org RUSTYSHADE delivery
SHA-256 52d07b3ef0c5f27d…387523 DriverInstaller.zip (RUSTYSHADE)
SHA-256 80fdde0dafa450ae…6a92e DriverInstaller.exe (RUSTYSHADE)
SHA-256 70fc6cba3c021889…18da31 Automata-20.exe (RUSTYMOVE)
Sched. Task StandAloneOneDriveUpdater-2626 RUSTYMOVE persistence
User-Agent SmartUploader PSNATCH / BASHNATCH exfiltration
Cloud URL clients-easy.s3.us-east-005.backblazeb2[.]com Payload staging

Full file hashes and the complete YARA rules are available in the Zscaler ThreatLabz original report.

What You Should Do: Sanjay Seth’s Defence Checklist

Operation RapidRust is not a theoretical risk. It is an active campaign. As a cybersecurity consultant who has spent thirty years building and defending Indian enterprise networks, I recommend the following immediate and medium-term actions:

Immediate (within 24 hours)

  1. Block the IoC domains — Add theprints[.]org, indiatodays[.]org, and officialinfo[.]org to your DNS sinkhole and FortiGate URL filter. Flag any lookups that already occurred in your DNS logs.
  2. Hunt for the scheduled task — Query all endpoints for a scheduled task named StandAloneOneDriveUpdater-2626. If found, isolate the machine immediately.
  3. Search logs for SmartUploader User-Agent — Run this query in your SIEM against proxy logs for the past 60 days. Any match is a confirmed PSNATCH or BASHNATCH infection.
  4. Audit USB policy enforcement — RUSTYMOVE propagates via removable media. If your endpoint controls allow unrestricted USB access, disable it on all high-risk workstations today.
  5. Check outbound GitHub API calls — On a government or defence network, there are very few reasons for a workstation to call api.github.com at 09:30–16:30 IST every weekday. Flag and investigate any such traffic.

Medium-Term (within 30 days)

  1. Enable full SSL/TLS inspection — RUSTYSHADE’s C2 is encrypted. Without TLS inspection on your FortiGate firewall, this traffic is invisible. This is not optional if you work with or adjacent to government entities.
  2. Implement Zero Trust Network Access (ZTNA) — Lateral movement via IPC$ and SMB null sessions—as documented in Operation RapidRust—is only possible because flat network architectures grant implicit trust to internal IP addresses. Zero Trust removes that assumption.
  3. Deploy Application Whitelisting — RUSTYMOVE and RUSTYSHADE both execute from user-writable paths. An application control policy that blocks unsigned executables from %APPDATA%, %TEMP%, and removable drives will stop this at the execution stage.
  4. Review CERT-In incident reporting readiness — If your organisation is covered by the CERT-In 2022 directions, a confirmed APT36 infection must be reported within six hours of detection. Have that runbook ready before you need it.
  5. Conduct spear-phishing simulation training — The initial access vector for Operation RapidRust is social engineering via convincing Indian media lures. Employees who can spot a typosquatted domain are the most cost-effective control you have.

Sources: The Hacker News | Zscaler ThreatLabz (primary research) | Security Boulevard | GBHackers

Frequently Asked Questions

Is Operation RapidRust targeting private sector companies in India, or only government?

The Zscaler report specifically identifies government and defence organisations in India and Afghanistan as primary targets. However, APT36 historically uses the private sector—particularly IT vendors, logistics companies, and hospitality providers with government contracts—as a stepping stone into protected networks. If your organisation has any contract or connectivity with Indian government entities, you are in the risk perimeter.

How does RUSTYSHADE hide its C2 traffic from a Next-Generation Firewall?

RUSTYSHADE communicates exclusively via the GitHub REST API over HTTPS. Because GitHub is a legitimate, widely-trusted service, most firewall policies either allow it outright or exempt it from TLS inspection. RUSTYSHADE exploits this by using attacker-controlled private repositories—repositories that are not publicly accessible and therefore cannot be blacklisted by URL category feeds. The only reliable way to detect or block this traffic is to enable deep packet inspection (DPI) with full TLS decryption and use anomaly-based behavioural analysis to flag workstations that call the GitHub API outside normal development workflows.

What makes RUSTYMOVE particularly dangerous in classified or air-gapped environments?

Air-gapped networks are assumed to be protected by physical isolation—no internet, no direct network path. RUSTYMOVE defeats this assumption by piggybacking on the human factor: a trusted employee carries a USB drive between an internet-connected workstation and an air-gapped machine. RUSTYMOVE stages itself on the drive invisibly, executes via an LNK file or scheduled task on insertion, and silently installs RUSTYSHADE on the isolated system. The infected machine then waits until it is reconnected to the internet—even briefly—to sync with the GitHub C2. This technique is a known APT pattern. The mitigation is strict USB policy enforcement and endpoint controls that prevent execution from removable media.

How is Operation RapidRust connected to earlier APT36 campaigns I may have read about?

APT36 has a long, well-documented history of targeting India. Previous campaigns used CrimsonRAT, ElizaRAT, and an older tool called GITSHELLPAD—which Zscaler describes as a functional predecessor to RUSTYSHADE. Operation RapidRust represents a deliberate technical upgrade: the shift to Rust provides better evasion, and the GitHub C2 method replaces older, more detectable C2 channels. The threat actor’s tactics, targeting, and operating hours are consistent with the group’s prior campaigns going back to 2013. This is an evolution, not a new group.


Operation RapidRust is a reminder that India’s government and defence sector faces persistent, well-funded, state-sponsored adversaries who continuously update their tooling. The controls that stopped APT36 in 2023 may not stop RUSTYSHADE in 2026. A comprehensive security assessment—covering your firewall policy, endpoint controls, USB governance, and TLS inspection—is the right starting point.

If you are responsible for network security in a government-adjacent or defence-supply-chain organisation in India and want an expert review of your current posture against APT-level threats, get in touch with Sanjay Seth for a security assessment. Thirty years of building and defending Indian enterprise networks, including ZTNA deployments and FortiGate hardening across multi-site environments—put that experience to work for you.