hacker-news · Crawled Sep 18, 2026

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

11 IoCs 1 Actors
Read original article ↗

AI Summary

Transparent Tribe (APT36), a Pakistan-aligned threat actor, has launched a new campaign dubbed Operation RapidRust, targeting government and defense entities in India and Afghanistan. The group deployed a Rust-based backdoor called RUSTYSHADE that uses private GitHub repositories for encrypted command-and-control (C2) communications. Additional tools include RUSTYMOVE, a USB propagation tool, and file stealers PSNATCH (PowerShell) and BASHNATCH (bash) for Windows and Linux systems. Attackers used typosquatted domains impersonating Indian news sites to host malicious payloads and conducted post-compromise activities including reconnaissance and lateral movement.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 11 extracted

Type Value Detail
Domain theprints[.]org Details →
Domain indiatodays[.]org Details →
Filename command.txt Details →
Filename results.txt Details →
Filename info.txt Details →
Filename heartbeat.txt Details →
Filename screenshot.png Details →
Filename webcam_photo.jpg Details →
Filename download.bin Details →
Filename DriverInstaller.zip Details →
Filename DocScanner-11-Aug-2026-5-37pm.pdf.LNK Details →

MITRE ATT&CK TTPs 1 techniques