APT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networks (opens in a new tab)
Why readAPT36 now ships a USB propagation utility built to cross into air-gapped Indian and Afghan government systems, which changes what removable-media controls have to stop.
Zscaler attributes a campaign it calls RapidRust to the Pakistan-linked group APT36, combining a backdoor, file stealers and a tool that spreads over removable drives to reach networks with no internet path. Command and staging infrastructure leans on private GitHub repositories, cloud-hosted payloads and domains impersonating Indian media outlets, so the traffic resembles ordinary browsing. This is aggregator coverage of a vendor report rather than primary analysis, so treat the Zscaler write-up as the source of record for indicators.
Indicators9
- Hashes
aade06ec611d69f1553035f22356ccf4ad4afe86a835bb2f7768862d358ebd8324c0590205bbeea42f481a3dd1b3f670aba481f7c5c8e897ef321d65188317be5a65a4d7f16f507a8ed515663a4f07050cd97a74- URLs
hxxps://clients-easy[.]s3[.]us-east-005[.]backblazeb2[.]com/Automata-20[.]ziphxxps://f005[.]backblazeb2[.]com/file/Clients-easy/DriverInstaller[.]zip- Domains
theprints[.]orgofficialinfo[.]orgindiatodays[.]org