Skip to content
APT36 Launches Operation RapidRust with New Rust Malware Tools

APT36 Launches Operation RapidRust with New Rust Malware Tools

First seen 18 Sep 2026, 16:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 18:54 UTC

In August 2026, the Pakistan-nexus threat actor APT36 initiated Operation RapidRust, targeting government and defense organizations in India and Afghanistan. The campaign introduced several new Rust-based malware tools, including the RUSTYSHADE backdoor and RUSTYMOVE propagation tool. APT36 also deployed file-stealing scripts named PSNATCH and BASHNATCH, which exfiltrate data through private GitHub repositories. The RUSTYSHADE backdoor utilizes the GitHub REST API for command-and-control communications and employs a hardcoded Personal Access Token (PAT) for authentication. The group has been observed attempting lateral movement within networks and spreading malware via removable media to reach air-gapped environments. Security professionals are advised to monitor GitHub API usage and implement strict controls on removable media to mitigate risks. The campaign is ongoing, with significant post-compromise activity reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-01
Operation RapidRust initiated
APT36 began targeting government and defense organizations in India and Afghanistan with new malware tools.
Zscaler
2026-09-16
Zscaler publishes findings
Zscaler ThreatLabz released a detailed analysis of APT36's new tooling and tactics in Operation RapidRust.
Zscaler
2026-09-18
Socprime reports on APT36 activity
Socprime confirmed ongoing APT36 operations and provided additional insights into the malware and attack vectors.
Socprime

More articles in this cluster (2)

Following this threat?

Track Apt36, Bashnatch and Backblaze in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed