APT36 Deploys Four New Tools in Operation RapidRust

Summary
Zscaler details APT36’s Operation RapidRust campaign targeting government and defense organizations in India and Afghanistan, including four new tools for backdoor access, file theft, and removable-media propagation.
Key points
- ThreatLabz observed APT36 activity from August 20 to September 1, 2026, targeting government and defense entities in India and Afghanistan.
- RUSTYSHADE is a Rust-based Windows backdoor that uses private GitHub repositories for encrypted command-and-control and can capture screenshots and webcam images.
- PSNATCH and Linux variant BASHNATCH scan configured locations for files and exfiltrate them to attacker-controlled GitHub repositories.
- RUSTYMOVE monitors removable drives and copies staged malicious files to them, supporting propagation to air-gapped networks.
- APT36 conducted system and network reconnaissance, created logon-triggered scheduled tasks, and attempted lateral movement through network shares.
- The campaign used typosquatted domains impersonating Indian news outlets and Backblaze to host payloads; Zscaler lists detections for the four tools.
Article Details
- Attack Vectors
- Attacker-controlled private repositories provide encrypted command delivery, command-output collection, and file exfiltration.
- An attacker-controlled gist supplies a next-stage file-stealing script, while cloud-hosted ZIP archives deliver additional payloads.
- Typosquatted domains impersonating Indian news outlets host intermediate scripts and next-stage payloads.
- Logon-triggered scheduled tasks launch malicious executables or retrieve and execute remote scripts while masquerading as legitimate updater tasks.
- Removable-media propagation copies a malicious archive and shortcut to external drives to support spread into air-gapped networks. ThreatLabz could not confirm the shortcut's exact target command.
- Operators attempted lateral movement through remote IPC$ connections, first using a null session and then specified administrator credentials.
- Defensive Notes
- The source reports platform detections for the backdoor, removable-media propagation component, and Windows and Linux file stealers.
- Persistence verification activity included querying scheduled-task definitions and checking command exit codes.
- Incremental file theft uses local tracking files that record file paths and modification timestamps, allowing previously collected files to be skipped unless modified.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | indiatodays[.]org | APT36-registered domain impersonating an Indian news outlet and staging malicious scripts and payloads. |
| DOMAIN | officialinfo[.]org | Domain explicitly listed as payload-staging infrastructure. |
| DOMAIN | theprints[.]org | APT36-registered domain impersonating an Indian news outlet and staging malicious scripts and payloads. |
| MD5 | 40a75f87f1e52c33df9ca733aaf8ebbb | Hash listed for DriverInstaller.zip, an archive containing RUSTYSHADE. |
| MD5 | aade06ec611d69f1553035f22356ccf4 | Hash listed for Automata-20.zip, an archive containing RUSTYMOVE. |
| MD5 | ae77f1834ccde53258bc27a779102af2 | Hash listed for DriverInstaller.exe, the RUSTYSHADE executable. |
| MD5 | f16f507a8ed515663a4f07050cd97a74 | Hash listed for Automata-20.exe, the RUSTYMOVE executable. |
| SHA1 | 00aff1a72c5d5635ab36ce2eb370718a7f0557a0 | Hash listed for DriverInstaller.zip, an archive containing RUSTYSHADE. |
| SHA1 | 00e1cc0fb1355c196c069791a02b4a5f3b57ae94 | Hash listed for Automata-20.exe, the RUSTYMOVE executable. |
| SHA1 | 761ccb15af1c3fe6e4365ddf65578966e4c84fc9 | Hash listed for DriverInstaller.exe, the RUSTYSHADE executable. |
| SHA1 | ad4afe86a835bb2f7768862d358ebd8324c05902 | Hash listed for Automata-20.zip, an archive containing RUSTYMOVE. |
| SHA256 | 05bbeea42f481a3dd1b3f670aba481f7c5c8e897ef321d65188317be5a65a4d7 | Hash listed for Automata-20.zip, an archive containing RUSTYMOVE. |
| SHA256 | 52d07b3ef0c5f27d082551d51027de452682e1fbd5bb38a897ea4b31bd387523 | Hash listed for DriverInstaller.zip, an archive containing RUSTYSHADE. |
| SHA256 | 70fc6cba3c2021889fb4093d0221dc6925818666df25718a630c562cac18da31 | Hash listed for Automata-20.exe, the RUSTYMOVE executable. |
| SHA256 | 80fdde0dafa450ae33937ccef752b46666da567926b2f39b37e02e77f9d6a92e | Hash listed for DriverInstaller.exe, the RUSTYSHADE executable. |
| URL | hxxps[:]//clients-easy[.]s3[.]us-east-005[.]backblazeb2[.]com/Automata-20[.]zip | Cloud-hosted payload URL used to download the archive containing RUSTYMOVE. |
| URL | hxxps[:]//f005[.]backblazeb2[.]com/file/Clients-easy/DriverInstaller[.]zip | Defanged payload-staging URL listed for the archive containing RUSTYSHADE. |
MITRE ATT&CK
T1005 · Data from Local SystemPSNATCH and BASHNATCH collect local files matching configured extensions and modification-time criteria.T1016 · System Network Configuration DiscoveryOperators used ipconfig and ipconfig /all to inspect network adapter configuration.T1018 · Remote System DiscoveryAPT36 swept local subnets with ping and Test-Connection and used NetBIOS queries to identify active machines.T1021.002 · SMB/Windows Admin SharesAPT36 attempted remote IPC$ connections with net use, first through a null session and then specified administrator credentials.T1033 · System Owner/User DiscoveryOperators ran whoami and inspected USERPROFILE to identify the current user.T1036.004 · Masquerade Task or ServiceMalicious scheduled tasks used OneDrive and Edge updater-style names to appear legitimate.T1046 · Network Service DiscoveryOperators probed discovered hosts on ports 445 and 135 to assess potential lateral-movement targets.T1053.005 · Scheduled TaskAPT36 created scheduled tasks that launch RUSTYMOVE or execute remote PowerShell payloads when a user logs on.T1057 · Process DiscoveryOperators ran tasklist to identify processes running on compromised machines.T1059.001 · PowerShellAPT36 used PowerShell to download payloads, register scheduled tasks, discover external drives, and execute file-stealing scripts.T1059.003 · Windows Command ShellRUSTYSHADE executes unrecognized command input through cmd.exe, and operators issued Windows shell reconnaissance commands.T1059.004 · Unix ShellBASHNATCH is a Bash script used to collect and exfiltrate files from Linux environments.T1069.001 · Local GroupsOperators used whoami /groups to inspect the current user's group memberships.T1070.004 · File DeletionOperators deleted archives, executables, a DLL, and tracking files associated with previously deployed tooling.T1082 · System Information DiscoveryOperators ran hostname and inspected environment variables to gather information about compromised systems.T1083 · File and Directory DiscoveryRUSTYSHADE lists directory contents and drive letters, while the file stealers recursively scan configured directories.T1091 · Replication Through Removable MediaRUSTYMOVE copies a RUSTYSHADE archive and malicious shortcut to removable drives to enable propagation, including into air-gapped networks.T1102.002 · Bidirectional CommunicationRUSTYSHADE retrieves encrypted commands and uploads encrypted results through attacker-controlled private GitHub repositories.T1105 · Ingress Tool TransferAPT36 downloaded RUSTYSHADE and RUSTYMOVE archives from Backblaze-hosted resources and retrieved PSNATCH from an attacker-controlled gist.T1113 · Screen CaptureRUSTYSHADE captures desktop screenshots through native GDI32 APIs and uploads encrypted screenshot data.T1120 · Peripheral Device DiscoveryRUSTYMOVE enumerates volumes, partitions, and disks to identify USB, SD, MMC, and IEEE 1394 external media.T1125 · Video CaptureRUSTYSHADE can capture webcam photos using WIA.CommonDialog and upload encrypted image data.T1135 · Network Share DiscoveryOperators used net view and net share to enumerate visible machines and network shares.T1560.001 · Archive via UtilityRUSTYSHADE uses Compress-Archive to compress a requested file before encrypting and uploading it.T1564.003 · Hidden WindowRUSTYMOVE launches its external-drive enumeration PowerShell script with WindowStyle Hidden.T1567.001 · Exfiltration to Code RepositoryPSNATCH exfiltrates collected files to private GitHub repositories through the GitHub Contents API.T1573.001 · Symmetric CryptographyRUSTYSHADE encrypts C2 messages with AES-256-GCM using a key derived from the hardcoded GitHub PAT.T1614 · System Location DiscoveryOperators queried public geolocation APIs for the infected machine's external IP address and geographic coordinates.
Threat Actors
Malware
BASHNATCHThe new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools.GITSHELLPADprivate GitHub repositories for C2 communication. Some of its functionality is similar to GITSHELLPAD, which we observed in the GOGITTER campaign. However, notable differences include support for encryptedPSNATCHactivity. The new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools.RUSTYMOVEas well as significant post-compromise activity. The new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools.RUSTYSHADEand post-compromise tools, as well as significant post-compromise activity. The new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools.
Vendors
BackblazeThe threat actor used private GitHub repositories for C2 communications and legitimate cloud storage platforms, including Backblaze, to host post-compromise tools.NamecheapThe campaign domains were registered under NameCheap and used to host intermediate PowerShell scripts and next-stage payloads. As shown in the table below, the domains impersonated popular Indian media organizations.ZscalerIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January
Products
GitHubRUSTYSHADE is a new Rust-based backdoor that abuses attacker-controlled private GitHub repositories for command-and-control (C2) and uses AES-256-GCM to encrypt C2 communications.LinuxBASHNATCH is a bash script similar to PSNATCH that targets Linux environments.Microsoft WindowsRUSTYSHADE is a new 64-bit Windows backdoor written in Rust that abuses attacker-controlled private GitHub repositories for C2 communication. Some of its functionality is similar to GITSHELLPAD, which we observed in the
Countries
Afghanistanand procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. During our investigation, ThreatLabz discovered new malware families and post-compromise tools, asIndiatechniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. During our investigation, ThreatLabz discovered new malware families and post-compromisePakistanIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January
Industries
Defenseupdated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. During our investigation, ThreatLabz discovered new malwareGovernmenttempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. During our investigation, ThreatLabz discovered new