The notorious threat group known as Transparent Tribe, also identified as APT36, has launched a new wave of cyber attacks targeting government and defense sectors in India and Afghanistan. This operation marks a significant development in their tactics, utilizing a suite of newly discovered tools collectively referred to as Operation RapidRust.
Emergence of New Tools in Cyber Espionage
The latest campaign by Transparent Tribe involves four previously undocumented tools: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. According to a report from Zscaler ThreatLabz, these tools are part of a sophisticated strategy aimed at compromising critical infrastructure in the affected regions.
RUSTYSHADE, a key component of this operation, is a Rust-based backdoor. It leverages private GitHub repositories for encrypted command-and-control (C2) communications. This approach mirrors the functionality of GITSHELLPAD, a Golang-based implant associated with the Gopher Strike campaign observed in 2025.
Innovative Use of GitHub in Cyber Attacks
A notable tactic employed by Transparent Tribe is the use of private GitHub repositories to store and manage encrypted C2 communications. This includes files such as command.txt for encrypted commands, and results.txt for encrypted outputs, among others. By using the GitHub REST API, the malware ensures seamless bidirectional communication.
Additionally, the group has utilized typosquatted domains to mimic Indian news outlets like The Print and India Today, furthering their ability to host malicious scripts and payloads undetected.
Impact of PSNATCH and BASHNATCH
PSNATCH and BASHNATCH, two other components of the operation, are designed to exfiltrate data from targeted systems. PSNATCH, a PowerShell-based stealer, scans directories for specific file types and uploads them to a private repository. Conversely, BASHNATCH operates similarly but is tailored for Linux environments.
RUSTYMOVE, another critical tool, is developed in Rust and focuses on spreading malware through USB drives. This tool monitors for removable media and deploys malicious files to ensure the persistence of the attack.
The campaign, which spanned from late August to early September 2026, highlights the group’s evolving tactics and persistent efforts to compromise high-value targets in South Asia. The attacks are meticulously timed, with C2 commands executed only during specific hours on weekdays.
This operation underscores Transparent Tribe’s continuous threat to regional stability, as they adapt and refine their techniques to remain effective against evolving cybersecurity defenses.
