APT36, a cyber threat group believed to be linked to Pakistan, is employing a new method to breach highly secure government networks. These networks, often air-gapped to prevent internet-based attacks, are now vulnerable due to APT36’s use of infected removable drives.
Targeted Campaign: RapidRust
The operation, known as RapidRust, specifically targets government entities in India and Afghanistan. Utilizing a combination of backdoor programs, file stealing software, and a USB-spreading mechanism, this campaign poses a significant risk to air-gapped systems. These systems, designed to be isolated, can be compromised if infected USB drives are used.
Reports indicate that Zscaler, a cybersecurity firm, identified this activity in August 2026. Their research attributes the operation to APT36, highlighting the toolkit’s capability to extract sensitive documents and scan local networks without a direct internet connection.
Technical Details and Impacts
Central to this campaign is the RUSTYMOVE tool, a lightweight Windows application developed in Rust. It continuously monitors removable media devices, such as USB drives, for new connections. Upon detecting a new device, it transfers files that include a backdoor disguised as a PDF shortcut. When users open this shortcut, the backdoor activates, turning the USB into a delivery tool.
The campaign also uses a scheduled task named StandAloneOneDriveUpdater-2626 to mimic legitimate updates, allowing the malware to operate stealthily. Security experts recommend restricting the use of removable media in sensitive environments and ensuring all devices are thoroughly scanned.
Broader Implications and Defense Strategies
This operation underscores the vulnerability of relying solely on physical isolation for security. APT36’s methodology resembles other campaigns, such as the Mustang Panda SnakeDisk operation, reinforcing the need for additional protective measures.
To defend against such threats, cybersecurity professionals advise implementing strict controls on removable media, monitoring network activity for unusual behaviors, and blocking known malicious domains and URLs. It is crucial for organizations, especially those handling classified data, to maintain robust network segmentation and employ comprehensive monitoring solutions.
The use of platforms like GitHub for command and control complicates detection, as legitimate traffic may obscure malicious activities. Security teams should be vigilant in reviewing repository accesses and monitoring for suspicious API usage.
Future Outlook and Recommendations
APT36’s tactics highlight a growing trend in cyber warfare where attackers leverage legitimate tools and platforms to mask their activities. As such threats evolve, it is imperative that organizations adapt their defensive strategies to anticipate and mitigate these sophisticated attack vectors.
For enhanced security, integrating threat intelligence tools that provide instant context for indicators of compromise (IoCs) can significantly reduce response times and improve the overall effectiveness of security operations.
