importantSYS.SOURCE: The Hacker News• 2026-09-18T20:54:16+05:30
APT36 Deploys Rust-Based Backdoor via Private GitHub C2 Infrastructure
APT36 employs a Rust-based backdoor (RUSTYSHADE) leveraging private GitHub repositories for encrypted command-and-control communications. The campaign targets government and defense entities in India and Afghanistan, utilizing typosquatted domains and file-stealing tools across Windows and Linux systems.
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.
The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation
*** END OF TRANSMISSION ***