APT36 Deploys Four New Tools in Operation RapidRust

· Original article ↗

Summary

Zscaler details APT36’s Operation RapidRust campaign targeting government and defense organizations in India and Afghanistan, including four new tools for backdoor access, file theft, and removable-media propagation.

Key points

  • ThreatLabz observed APT36 activity from August 20 to September 1, 2026, targeting government and defense entities in India and Afghanistan.
  • RUSTYSHADE is a Rust-based Windows backdoor that uses private GitHub repositories for encrypted command-and-control and can capture screenshots and webcam images.
  • PSNATCH and Linux variant BASHNATCH scan configured locations for files and exfiltrate them to attacker-controlled GitHub repositories.
  • RUSTYMOVE monitors removable drives and copies staged malicious files to them, supporting propagation to air-gapped networks.
  • APT36 conducted system and network reconnaissance, created logon-triggered scheduled tasks, and attempted lateral movement through network shares.
  • The campaign used typosquatted domains impersonating Indian news outlets and Backblaze to host payloads; Zscaler lists detections for the four tools.

Article Details

Attack Vectors
  • Attacker-controlled private repositories provide encrypted command delivery, command-output collection, and file exfiltration.
  • An attacker-controlled gist supplies a next-stage file-stealing script, while cloud-hosted ZIP archives deliver additional payloads.
  • Typosquatted domains impersonating Indian news outlets host intermediate scripts and next-stage payloads.
  • Logon-triggered scheduled tasks launch malicious executables or retrieve and execute remote scripts while masquerading as legitimate updater tasks.
  • Removable-media propagation copies a malicious archive and shortcut to external drives to support spread into air-gapped networks. ThreatLabz could not confirm the shortcut's exact target command.
  • Operators attempted lateral movement through remote IPC$ connections, first using a null session and then specified administrator credentials.
Defensive Notes
  • The source reports platform detections for the backdoor, removable-media propagation component, and Windows and Linux file stealers.
  • Persistence verification activity included querying scheduled-task definitions and checking command exit codes.
  • Incremental file theft uses local tracking files that record file paths and modification timestamps, allowing previously collected files to be skipped unless modified.

Indicators of compromise

TypeIndicatorContext
DOMAINindiatodays[.]orgAPT36-registered domain impersonating an Indian news outlet and staging malicious scripts and payloads.
DOMAINofficialinfo[.]orgDomain explicitly listed as payload-staging infrastructure.
DOMAINtheprints[.]orgAPT36-registered domain impersonating an Indian news outlet and staging malicious scripts and payloads.
MD540a75f87f1e52c33df9ca733aaf8ebbbHash listed for DriverInstaller.zip, an archive containing RUSTYSHADE.
MD5aade06ec611d69f1553035f22356ccf4Hash listed for Automata-20.zip, an archive containing RUSTYMOVE.
MD5ae77f1834ccde53258bc27a779102af2Hash listed for DriverInstaller.exe, the RUSTYSHADE executable.
MD5f16f507a8ed515663a4f07050cd97a74Hash listed for Automata-20.exe, the RUSTYMOVE executable.
SHA100aff1a72c5d5635ab36ce2eb370718a7f0557a0Hash listed for DriverInstaller.zip, an archive containing RUSTYSHADE.
SHA100e1cc0fb1355c196c069791a02b4a5f3b57ae94Hash listed for Automata-20.exe, the RUSTYMOVE executable.
SHA1761ccb15af1c3fe6e4365ddf65578966e4c84fc9Hash listed for DriverInstaller.exe, the RUSTYSHADE executable.
SHA1ad4afe86a835bb2f7768862d358ebd8324c05902Hash listed for Automata-20.zip, an archive containing RUSTYMOVE.
SHA25605bbeea42f481a3dd1b3f670aba481f7c5c8e897ef321d65188317be5a65a4d7Hash listed for Automata-20.zip, an archive containing RUSTYMOVE.
SHA25652d07b3ef0c5f27d082551d51027de452682e1fbd5bb38a897ea4b31bd387523Hash listed for DriverInstaller.zip, an archive containing RUSTYSHADE.
SHA25670fc6cba3c2021889fb4093d0221dc6925818666df25718a630c562cac18da31Hash listed for Automata-20.exe, the RUSTYMOVE executable.
SHA25680fdde0dafa450ae33937ccef752b46666da567926b2f39b37e02e77f9d6a92eHash listed for DriverInstaller.exe, the RUSTYSHADE executable.
URLhxxps[:]//clients-easy[.]s3[.]us-east-005[.]backblazeb2[.]com/Automata-20[.]zipCloud-hosted payload URL used to download the archive containing RUSTYMOVE.
URLhxxps[:]//f005[.]backblazeb2[.]com/file/Clients-easy/DriverInstaller[.]zipDefanged payload-staging URL listed for the archive containing RUSTYSHADE.

MITRE ATT&CK

T1005 · Data from Local SystemPSNATCH and BASHNATCH collect local files matching configured extensions and modification-time criteria.T1016 · System Network Configuration DiscoveryOperators used ipconfig and ipconfig /all to inspect network adapter configuration.T1018 · Remote System DiscoveryAPT36 swept local subnets with ping and Test-Connection and used NetBIOS queries to identify active machines.T1021.002 · SMB/Windows Admin SharesAPT36 attempted remote IPC$ connections with net use, first through a null session and then specified administrator credentials.T1033 · System Owner/User DiscoveryOperators ran whoami and inspected USERPROFILE to identify the current user.T1036.004 · Masquerade Task or ServiceMalicious scheduled tasks used OneDrive and Edge updater-style names to appear legitimate.T1046 · Network Service DiscoveryOperators probed discovered hosts on ports 445 and 135 to assess potential lateral-movement targets.T1053.005 · Scheduled TaskAPT36 created scheduled tasks that launch RUSTYMOVE or execute remote PowerShell payloads when a user logs on.T1057 · Process DiscoveryOperators ran tasklist to identify processes running on compromised machines.T1059.001 · PowerShellAPT36 used PowerShell to download payloads, register scheduled tasks, discover external drives, and execute file-stealing scripts.T1059.003 · Windows Command ShellRUSTYSHADE executes unrecognized command input through cmd.exe, and operators issued Windows shell reconnaissance commands.T1059.004 · Unix ShellBASHNATCH is a Bash script used to collect and exfiltrate files from Linux environments.T1069.001 · Local GroupsOperators used whoami /groups to inspect the current user's group memberships.T1070.004 · File DeletionOperators deleted archives, executables, a DLL, and tracking files associated with previously deployed tooling.T1082 · System Information DiscoveryOperators ran hostname and inspected environment variables to gather information about compromised systems.T1083 · File and Directory DiscoveryRUSTYSHADE lists directory contents and drive letters, while the file stealers recursively scan configured directories.T1091 · Replication Through Removable MediaRUSTYMOVE copies a RUSTYSHADE archive and malicious shortcut to removable drives to enable propagation, including into air-gapped networks.T1102.002 · Bidirectional CommunicationRUSTYSHADE retrieves encrypted commands and uploads encrypted results through attacker-controlled private GitHub repositories.T1105 · Ingress Tool TransferAPT36 downloaded RUSTYSHADE and RUSTYMOVE archives from Backblaze-hosted resources and retrieved PSNATCH from an attacker-controlled gist.T1113 · Screen CaptureRUSTYSHADE captures desktop screenshots through native GDI32 APIs and uploads encrypted screenshot data.T1120 · Peripheral Device DiscoveryRUSTYMOVE enumerates volumes, partitions, and disks to identify USB, SD, MMC, and IEEE 1394 external media.T1125 · Video CaptureRUSTYSHADE can capture webcam photos using WIA.CommonDialog and upload encrypted image data.T1135 · Network Share DiscoveryOperators used net view and net share to enumerate visible machines and network shares.T1560.001 · Archive via UtilityRUSTYSHADE uses Compress-Archive to compress a requested file before encrypting and uploading it.T1564.003 · Hidden WindowRUSTYMOVE launches its external-drive enumeration PowerShell script with WindowStyle Hidden.T1567.001 · Exfiltration to Code RepositoryPSNATCH exfiltrates collected files to private GitHub repositories through the GitHub Contents API.T1573.001 · Symmetric CryptographyRUSTYSHADE encrypts C2 messages with AES-256-GCM using a key derived from the hardcoded GitHub PAT.T1614 · System Location DiscoveryOperators queried public geolocation APIs for the infected machine's external IP address and geographic coordinates.

Threat Actors

Malware

Vendors

Products

Countries

Industries

Related Articles