hacker-news · Crawled Sep 18, 2026
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
11 IoCs 1 Actors
Read original article ↗
AI Summary
Transparent Tribe (APT36), a Pakistan-aligned threat actor, has launched a new campaign dubbed Operation RapidRust, targeting government and defense entities in India and Afghanistan. The group deployed a Rust-based backdoor called RUSTYSHADE that uses private GitHub repositories for encrypted command-and-control (C2) communications. Additional tools include RUSTYMOVE, a USB propagation tool, and file stealers PSNATCH (PowerShell) and BASHNATCH (bash) for Windows and Linux systems. Attackers used typosquatted domains impersonating Indian news sites to host malicious payloads and conducted post-compromise activities including reconnaissance and lateral movement.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 11 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | theprints[.]org | Details → |
| Domain | indiatodays[.]org | Details → |
| Filename | command.txt | Details → |
| Filename | results.txt | Details → |
| Filename | info.txt | Details → |
| Filename | heartbeat.txt | Details → |
| Filename | screenshot.png | Details → |
| Filename | webcam_photo.jpg | Details → |
| Filename | download.bin | Details → |
| Filename | DriverInstaller.zip | Details → |
| Filename | DocScanner-11-Aug-2026-5-37pm.pdf.LNK | Details → |