Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Hanwha Ocean’s design solution allowing LNG carrier’s switch to ammonia gets ABS’ thumbs-up

    September 18, 2026

    Judge Denies Efforts to End Oversight of Maricopa County Sheriff’s Office — ProPublica

    September 18, 2026

    Review: Rozina Ali’s ‘Seasons of Fury’ Sheds New Light on Islamophobia Before and After 9/11

    September 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Hanwha Ocean’s design solution allowing LNG carrier’s switch to ammonia gets ABS’ thumbs-up
    • Judge Denies Efforts to End Oversight of Maricopa County Sheriff’s Office — ProPublica
    • Review: Rozina Ali’s ‘Seasons of Fury’ Sheds New Light on Islamophobia Before and After 9/11
    • Trump on war in Iran, Houthi advance in Yemen: ‘It’ll all work out’ – live | Trump administration
    • ‘There are no decent parties left’: Sham elections underscore Putin’s grip on Russia – POLITICO
    • Disabled people need right to travel abroad, say UK MPs amid ‘ridiculous’ restrictions row | Disability
    • ‘A critical moment’: concern UK is not up to speed in acting on AI risks | AI (artificial intelligence)
    • Xi’s edge over Trump on AI
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 18, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 18, 2026Malware / Cyber Espionage

    The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.

    The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation RapidRust.

    “APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan,” Sudeep Singh, senior manager of APT Research at Zscaler ThreatLabz, said in a technical report published this week.

    The discovery comes a little over a month after Acronis Threat Research Unit (TRU) tied the long-running persistent threat group to another campaign aimed at Afghan telecom providers and South Asian critical infrastructure organizations using a backdoor called PATCHCORD.

    Cybersecurity

    A notable aspect of the campaign is the threat actor’s use of private GitHub repositories for command-and-control (C2) and the registration of typosquatted domains impersonating popular Indian news organizations like The Print and India Today to host malicious PowerShell scripts and payloads –

    • theprints[.]org, which mimics The Print (“theprint[.]in”)
    • indiatodays[.]org, which mimics India Today (“indiatoday[.]in”)

    Among the four newly identified malware families, one is a backdoor, another is a lateral movement utility, while the remaining two are file-stealing programs designed for Windows and Linux systems.

    RUSTYSHADE, as the name implies, is a Rust-based backdoor that makes use of attacker-controlled private GitHub repositories for encrypted C2 communications. It shares some level of functionality overlap with GITSHELLPAD, a Golang implant that was observed in September 2025 in connection with a campaign known as Gopher Strike.

    Specifically, the malware parses and writes certain files in the private GitHub repository for bidirectional communication using the GitHub REST API. The names of the files are below –

    • command.txt, for storing encrypted C2 commands
    • results.txt, for storing encrypted command output
    • info.txt, to store system reconnaissance data
    • heartbeat.txt, for keepalive beaconing to confirm active infection
    • screenshot.png, for encrypted desktop screenshot
    • webcam_photo.jpg, for encrypted webcam capture
    • download.bin, for encrypted exfiltrated file contents

    The commands allow RUSTYSHADE to take screenshots, capture a webcam photo, perform file operations, and run commands in the background.

    As part of post-compromise activity, the threat actor has been observed fetching a file stealer from an attacker-controlled GitHub gist that comes in two variants for targeting both Windows and Linux environments –

    • PSNATCH, a PowerShell stealer that recursively scans preconfigured directories for Microsoft Office documents, images, archives, media, executables, scripts, and databases that were modified within the last three months and exfiltrates them to a private repository named after the infected machine. The file collection is limited to 1 GB per file and 5 GB per execution.
    • BASHNATCH, a bash script similar to PSNATCH that targets Linux systems
    Cybersecurity

    Perhaps the most interesting of the lot is RUSTYMOVE, a lightweight 64-bit Windows USB propagation tool developed in Rust. Its main responsibility is to continuously monitor for external removable media using a PowerShell script and copy two pre-staged malicious files to the root directory of each detected external drive –

    • DriverInstaller.zip, which contains RUSTYSHADE
    • DocScanner-11-Aug-2026-5-37pm.pdf.LNK, which is suspected to contain a command to execute RUSTYSHADE after extraction

    Post-compromise activity from APT36 operators involves system, user, and network reconnaissance, followed by the deployment of next-stage payloads. A significant portion of the actions took place between August 20 and September 1, 2026, with the C2 commands issued only between 4 a.m. and 11 a.m. UTC and only on weekdays.

    “This campaign demonstrates that APT36 continues to target government and defense entities in India and Afghanistan while maintaining high operational tempo and evolving TTPs,” Singh said.

    Backdoor Deploys GitHub private Repositories Rust Transparent Tribe
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

    Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

    Secure enterprise sharing with access reviews for Microsoft 365

    Webinar: Which Google Workspace security controls actually matter?

    ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

    WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Hanwha Ocean’s design solution allowing LNG carrier’s switch to ammonia gets ABS’ thumbs-up

    September 18, 2026

    Judge Denies Efforts to End Oversight of Maricopa County Sheriff’s Office — ProPublica

    September 18, 2026

    Review: Rozina Ali’s ‘Seasons of Fury’ Sheds New Light on Islamophobia Before and After 9/11

    September 18, 2026

    Trump on war in Iran, Houthi advance in Yemen: ‘It’ll all work out’ – live | Trump administration

    September 18, 2026
    Latest Posts

    Texas deputy used 83K Flock cameras to find woman who had abortion. Was it a welfare check, as he claimed?

    August 4, 2026

    Trump’s Seabed Mining Order Is an Ecological and Political Disaster

    August 4, 2026

    ExxonMobil picks Sercel technology to support operations offshore Guyana

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Hanwha Ocean’s design solution allowing LNG carrier’s switch to ammonia gets ABS’ thumbs-up

    September 18, 2026

    Judge Denies Efforts to End Oversight of Maricopa County Sheriff’s Office — ProPublica

    September 18, 2026

    Review: Rozina Ali’s ‘Seasons of Fury’ Sheds New Light on Islamophobia Before and After 9/11

    September 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.