Skip to content
RegionSouth Asia

MediumII Cyber Warfare & Critical Infrastructure17 September 2026, Thursday

Pakistan-linked APT36 targeted government and defence organisations in India and Afghanistan with 4 new Rust-based tools

According to Zscaler ThreatLabz, Pakistan-linked APT36 attacked government and defence organisations in India and Afghanistan in August 2026 with 4 new tools. The RUSTYSHADE backdoor receives its commands through private GitHub repositories; activity peaked between 20 August and 1 September.

NEW DELHI

According to reports by GBHackers on 17 September and The Hacker News on 18 September 2026, Zscaler ThreatLabz documented 4 new tools in a campaign it named Operation RapidRust: the 64-bit Windows backdoor RUSTYSHADE, RUSTYMOVE, which spreads via removable media, and the file stealers PSNATCH for Windows and BASHNATCH for Linux. RUSTYSHADE communicates with AES-256-GCM encryption through command and result files in private GitHub repositories. PSNATCH targets documents modified in the last 120 days and collects data with a limit of 1 GB per file and 5 GB per run.

The attackers registered at least 3 domains impersonating Indian news sites, including addresses mimicking The Print and India Today. According to timestamp analysis, commands were issued only on weekdays between 04:00 and 11:00 UTC, with peak activity between 20 August and 1 September 2026. RUSTYMOVE spreads to USB, SD and MMC drives through a scheduled task disguised as a OneDrive updater with the suffix 2626.

How many organisations the campaign successfully compromised was not disclosed in the sources and could not be verified. The development of a separate stealer for Linux indicates that Linux-based workstations in Indian government and defence networks are being targeted.

Talay assessment

Bottom line

With 4 tools that hide in legitimate GitHub traffic and cover both Windows and Linux, APT36 is seeking persistent access to government and defence networks in India. Cyber espionage along the India–Pakistan axis is not losing momentum; commands being issued only on weekdays between 04:00 and 11:00 UTC point to a regular, office-hours-style operation. The most likely path is for the campaign to continue with new domains.

Likely effects

  • Indian defence networksNegative1–6 months

    RUSTYMOVE, spreading via USB, also carries the risk of penetrating air-gapped defence networks; removable media control becomes a priority again.

  • Cloud service abuseNegative1–6 months

    Moving command traffic to private GitHub repositories makes it harder for organisations to detect it without blocking legitimate developer traffic.

  • Turkish public institutionsUncertain1–6 months

    The use of GitHub and similar legitimate services as command channels shows that defences relying solely on domain blocking would also prove inadequate in Turkish public networks.

Possibilities, ranked

  1. 1
    Campaign continues on new infrastructure60%

    APT36 abandons the 3 exposed domains and keeps using the same tools with new impersonating domains.

    Watch: New domain registrations impersonating Indian news sites

  2. 2
    Official advisory issued30%

    CERT-In or Indian defence bodies issue an official advisory on RUSTYSHADE and RUSTYMOVE.

    Watch: Operation RapidRust indicators in CERT-In advisories

  3. 3
    Activity pauses temporarily10%

    After the exposure, the operators go quiet for a few weeks.

    Watch: Security firms reporting a drop in APT36 telemetry

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • New malicious tools 4
  • Data limit per run 5 GB

Sources

  1. The Hacker News — Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
  2. GBHackers — APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal