Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
APT36’s USB Malware Threatens Secure Networks

APT36’s USB Malware Threatens Secure Networks

Posted on September 17, 2026 By CWS

APT36, a cyber threat group believed to be linked to Pakistan, is employing a new method to breach highly secure government networks. These networks, often air-gapped to prevent internet-based attacks, are now vulnerable due to APT36’s use of infected removable drives.

Targeted Campaign: RapidRust

The operation, known as RapidRust, specifically targets government entities in India and Afghanistan. Utilizing a combination of backdoor programs, file stealing software, and a USB-spreading mechanism, this campaign poses a significant risk to air-gapped systems. These systems, designed to be isolated, can be compromised if infected USB drives are used.

Reports indicate that Zscaler, a cybersecurity firm, identified this activity in August 2026. Their research attributes the operation to APT36, highlighting the toolkit’s capability to extract sensitive documents and scan local networks without a direct internet connection.

Technical Details and Impacts

Central to this campaign is the RUSTYMOVE tool, a lightweight Windows application developed in Rust. It continuously monitors removable media devices, such as USB drives, for new connections. Upon detecting a new device, it transfers files that include a backdoor disguised as a PDF shortcut. When users open this shortcut, the backdoor activates, turning the USB into a delivery tool.

The campaign also uses a scheduled task named StandAloneOneDriveUpdater-2626 to mimic legitimate updates, allowing the malware to operate stealthily. Security experts recommend restricting the use of removable media in sensitive environments and ensuring all devices are thoroughly scanned.

Broader Implications and Defense Strategies

This operation underscores the vulnerability of relying solely on physical isolation for security. APT36’s methodology resembles other campaigns, such as the Mustang Panda SnakeDisk operation, reinforcing the need for additional protective measures.

To defend against such threats, cybersecurity professionals advise implementing strict controls on removable media, monitoring network activity for unusual behaviors, and blocking known malicious domains and URLs. It is crucial for organizations, especially those handling classified data, to maintain robust network segmentation and employ comprehensive monitoring solutions.

The use of platforms like GitHub for command and control complicates detection, as legitimate traffic may obscure malicious activities. Security teams should be vigilant in reviewing repository accesses and monitoring for suspicious API usage.

Future Outlook and Recommendations

APT36’s tactics highlight a growing trend in cyber warfare where attackers leverage legitimate tools and platforms to mask their activities. As such threats evolve, it is imperative that organizations adapt their defensive strategies to anticipate and mitigate these sophisticated attack vectors.

For enhanced security, integrating threat intelligence tools that provide instant context for indicators of compromise (IoCs) can significantly reduce response times and improve the overall effectiveness of security operations.

Cyber Security News Tags:Afghanistan, air-gapped networks, APT36, cyber attack, Cybersecurity, India, Pakistan, RUSTYMOVE, RUSTYSHADE, threat group, USB malware

Post navigation

Previous Post: AWS Confirms Data Loss in War-Affected Data Centers
Next Post: Critical Flaw in Check Point Servers Enables Code Execution

Related Posts

Hackers Deliver SSH-Tor Backdoor Via Weaponized Military Documents in ZIP Files Hackers Deliver SSH-Tor Backdoor Via Weaponized Military Documents in ZIP Files Cyber Security News
Critical Microsoft Entra ID Vulnerability Exploited Critical Microsoft Entra ID Vulnerability Exploited Cyber Security News
AI-Coded Applications: Security Challenges Uncovered AI-Coded Applications: Security Challenges Uncovered Cyber Security News
Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges Cyber Security News
Critical BIND 9 Vulnerabilities Threaten DNS Security Critical BIND 9 Vulnerabilities Threaten DNS Security Cyber Security News
Cobalt Strike 4.12 Released With New Process Injection, UAC Bypasses and Malleable C2 Options Cobalt Strike 4.12 Released With New Process Injection, UAC Bypasses and Malleable C2 Options Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaws in BIND DNS Servers Threaten Security
  • Orkes Conductor Flaw Exploited in Recent Cyber Attacks
  • Iran-Affiliated Hackers Exploit Telegram for Data Breaches
  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaws in BIND DNS Servers Threaten Security
  • Orkes Conductor Flaw Exploited in Recent Cyber Attacks
  • Iran-Affiliated Hackers Exploit Telegram for Data Breaches
  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark