A Pakistan-aligned hacking group known as Transparent Tribe has launched a fresh wave of cyber attacks against government and defense organizations in India and Afghanistan using four previously undocumented malware tools, according to a technical report published this week by Zscaler ThreatLabz. The campaign, dubbed Operation RapidRust, deploys sophisticated programs called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH to infiltrate networks, steal files, and spread across systems. The threat group, also tracked as APT36 and Earth Karkaddan, continues to show high operational tempo and evolving attack methods in its continued targeting of the region.
The four malware families serve distinct functions in the attack chain. RUSTYSHADE is a backdoor written in Rust that uses attacker-controlled private GitHub repositories for encrypted command-and-control communications, parsing and writing specific files like command.txt, results.txt, info.txt, heartbeat.txt, screenshot.png, webcam_photo.jpg, and download.bin for bidirectional communication through the GitHub REST API. RUSTYMOVE is a lightweight 64-bit Windows USB propagation tool that continuously monitors for removable media and copies two malicious files—DriverInstaller.zip containing RUSTYSHADE and a deceptive LNK file named DocScanner-11-Aug-2026-5-37pm.pdf.LNK—to the root directory of each detected external drive. PSNATCH and BASHNATCH are file-stealing programs targeting Windows and Linux systems respectively, with the PowerShell-based PSNATCH recursively scanning preconfigured directories for Office documents, images, archives, media, executables, scripts, and databases modified within the last three months and exfiltrating them to private repositories, limited to 1 GB per file and 5 GB per execution.
The attackers registered typosquatted domains mimicking prominent Indian news outlets to host malicious PowerShell scripts and payloads. "APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan," Sudeep Singh, senior manager of APT Research at Zscaler ThreatLabz, stated. The domains theprints[.]org and indiatodays[.]org impersonated The Print and India Today, respectively. A significant portion of the malicious activity occurred between August 20 and September 1, 2026, with command-and-control instructions issued exclusively between 4 a.m. and 11 a.m. UTC and only on weekdays.
The campaign demonstrates that the threat group remains focused on government and defense targets while continuously refining its attack infrastructure and techniques. The use of GitHub repositories for command-and-control represents an evolution from earlier campaigns, with RUSTYSHADE sharing functional overlap with GITSHELLPAD, a Golang implant observed in September 2025 during a campaign called Gopher Strike. Post-compromise operations follow a pattern of system, user, and network reconnaissance before deploying additional payloads. The discovery arrives roughly a month after Acronis Threat Research Unit linked the same persistent threat group to another operation aimed at Afghan telecom providers and South Asian critical infrastructure organizations using a backdoor called PATCHCORD. The weekday-only, morning-hour operational schedule and the multi-month file collection window suggest the attackers are balancing stealth with comprehensive data theft across compromised networks. Organizations defending against state-aligned adversaries face a persistent challenge as attackers migrate to harder-to-detect infrastructure and cross-platform tools, forcing security teams to monitor both conventional network traffic and legitimate developer services that can be weaponized for covert communications.

