Socprime APT36 Launches Operation RapidRust with New Rust Malware Tools
Article Content
- •APT36 is targeting Indian and Afghan government and defense sectors.
- •New malware tools include RUSTYSHADE backdoor and RUSTYMOVE propagation tool.
- •Malware exfiltrates data via private GitHub repositories.
In August 2026, the Pakistan-nexus threat actor APT36 initiated Operation RapidRust, targeting government and defense organizations in India and Afghanistan. The campaign introduced several new Rust-based malware tools, including the RUSTYSHADE backdoor and RUSTYMOVE propagation tool. APT36 also deployed file-stealing scripts named PSNATCH and BASHNATCH, which exfiltrate data through private GitHub repositories. The RUSTYSHADE backdoor utilizes the GitHub REST API for command-and-control communications and employs a hardcoded Personal Access Token (PAT) for authentication. The group has been observed attempting lateral movement within networks and spreading malware via removable media to reach air-gapped environments. Security professionals are advised to monitor GitHub API usage and implement strict controls on removable media to mitigate risks. The campaign is ongoing, with significant post-compromise activity reported.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Apt36, Bashnatch and Backblaze in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…