Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Transparent Tribe Unveils New Rust Backdoor Strategy

Transparent Tribe Unveils New Rust Backdoor Strategy

Posted on September 18, 2026 By CWS

The notorious threat group known as Transparent Tribe, also identified as APT36, has launched a new wave of cyber attacks targeting government and defense sectors in India and Afghanistan. This operation marks a significant development in their tactics, utilizing a suite of newly discovered tools collectively referred to as Operation RapidRust.

Emergence of New Tools in Cyber Espionage

The latest campaign by Transparent Tribe involves four previously undocumented tools: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. According to a report from Zscaler ThreatLabz, these tools are part of a sophisticated strategy aimed at compromising critical infrastructure in the affected regions.

RUSTYSHADE, a key component of this operation, is a Rust-based backdoor. It leverages private GitHub repositories for encrypted command-and-control (C2) communications. This approach mirrors the functionality of GITSHELLPAD, a Golang-based implant associated with the Gopher Strike campaign observed in 2025.

Innovative Use of GitHub in Cyber Attacks

A notable tactic employed by Transparent Tribe is the use of private GitHub repositories to store and manage encrypted C2 communications. This includes files such as command.txt for encrypted commands, and results.txt for encrypted outputs, among others. By using the GitHub REST API, the malware ensures seamless bidirectional communication.

Additionally, the group has utilized typosquatted domains to mimic Indian news outlets like The Print and India Today, furthering their ability to host malicious scripts and payloads undetected.

Impact of PSNATCH and BASHNATCH

PSNATCH and BASHNATCH, two other components of the operation, are designed to exfiltrate data from targeted systems. PSNATCH, a PowerShell-based stealer, scans directories for specific file types and uploads them to a private repository. Conversely, BASHNATCH operates similarly but is tailored for Linux environments.

RUSTYMOVE, another critical tool, is developed in Rust and focuses on spreading malware through USB drives. This tool monitors for removable media and deploys malicious files to ensure the persistence of the attack.

The campaign, which spanned from late August to early September 2026, highlights the group’s evolving tactics and persistent efforts to compromise high-value targets in South Asia. The attacks are meticulously timed, with C2 commands executed only during specific hours on weekdays.

This operation underscores Transparent Tribe’s continuous threat to regional stability, as they adapt and refine their techniques to remain effective against evolving cybersecurity defenses.

The Hacker News Tags:Afghanistan, APT36, cyber attacks, cyber espionage, cyber security, GitHub, India, Malware, RustysShade, Transparent Tribe

Post navigation

Previous Post: Top Container Registry Security Tools in 2026
Next Post: Brevo Security Breach Impacts Over 100,000 Websites

Related Posts

Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across Africa Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across Africa The Hacker News
Cisco Patches Actively Exploited SD-WAN Vulnerability Cisco Patches Actively Exploited SD-WAN Vulnerability The Hacker News
Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users The Hacker News
Critical PHP Composer Vulnerabilities Patched Critical PHP Composer Vulnerabilities Patched The Hacker News
Gravity SMTP Plugin Vulnerability Exposes API Keys Gravity SMTP Plugin Vulnerability Exposes API Keys The Hacker News
Google and Rivals Launch Advanced Cybersecurity AI Models Google and Rivals Launch Advanced Cybersecurity AI Models The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Feral Wolf Ransomware Exploits Exposed Business Systems
  • Abandoned CDN Domain Re-Registered, Impacting Thousands
  • Microsoft Patches Severe Azure AI Foundry Vulnerability
  • Brevo Security Breach Impacts Over 100,000 Websites
  • Transparent Tribe Unveils New Rust Backdoor Strategy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark