Threats · 3 days ago
Zscaler says Transparent Tribe, also tracked as APT36 and Earth Karkaddan, ran Operation RapidRust against government and defense targets in India and Afghanistan using four previously undocumented tools: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The campaign spans August 20 to September 1, 2026.
The main trick is simple: RUSTYSHADE stores encrypted commands and results in files inside a private GitHub repository and exchanges them through the GitHub REST API, so the control traffic blends into ordinary GitHub use. Zscaler also saw typosquatted Indian news domains staging PowerShell payloads, while the other tools handle movement and file theft on Windows and Linux.
For defenders, the durable issue is not just the new malware names but the trust wrapper around the channel. If endpoints can reach GitHub, a private repository can carry command-and-control without looking like a custom beacon, and the campaign shows Transparent Tribe turning fast to separate implants for control, movement, and theft.
1 source covering this story
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
Transparent Tribe uses four newly identified malware families in attacks on government and defense entities in India and Afghanistan.
Part of the PlainSec briefing for 2026-09-19