Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH (opens in a new tab)
Why readFirst technical breakdown of APT36's new Rust toolchain, including a backdoor that uses attacker-controlled private GitHub repos for command and control.
Zscaler ThreatLabz tracked August 2026 activity by the Pakistan-nexus actor APT36 against Indian and Afghan government and defence targets, naming it Operation RapidRust. The campaign introduces four previously undocumented tools: the Rust-based RUSTYSHADE backdoor, the RUSTYMOVE post-compromise utility, and the PSNATCH and BASHNATCH file stealers. RUSTYSHADE's abuse of private GitHub repositories for C2 is the detection-relevant detail, since that traffic blends with normal developer activity on allowlisted domains.
Indicators11
- Hashes
52d07b3ef0c5f27d082551d51027de452682e1fbd5bb38a897ea4b31bd38752380fdde0dafa450ae33937ccef752b46666da567926b2f39b37e02e77f9d6a92eaade06ec611d69f1553035f22356ccf4ad4afe86a835bb2f7768862d358ebd8324c0590205bbeea42f481a3dd1b3f670aba481f7c5c8e897ef321d65188317be5a65a4d7f16f507a8ed515663a4f07050cd97a7400e1cc0fb1355c196c069791a02b4a5f3b57ae9470fc6cba3c2021889fb4093d0221dc6925818666df25718a630c562cac18da31- URLs
hxxps://f005[.]backblazeb2[.]com/file/Clients-easy/DriverInstaller[.]ziphxxps://clients-easy[.]s3[.]us-east-005[.]backblazeb2[.]com/Automata-20[.]zip- Domains
indiatodays[.]org