Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
In August 2026, the Pakistan-nexus threat actor APT36 launched Operation RapidRust, targeting government and defense organizations in India and Afghanistan with an updated arsenal of custom tools. The campaign introduced RUSTYSHADE, a Rust-based backdoor leveraging private GitHub repositories for command-and-control with AES-256-GCM encryption. Additional tools included RUSTYMOVE for USB-based lateral movement to air-gapped networks, PSNATCH and BASHNATCH for file exfiltration from Windows and Linux systems respectively. The attackers registered typosquatted domains impersonating Indian news outlets to stage malicious PowerShell scripts. Post-compromise activities revealed systematic network reconnaissance, credential harvesting, and lateral movement attempts, with operations conducted exclusively on weekdays between 4:00-11:00 UTC, demonstrating disciplined operational security and sustained targeting of South Asian government infrastructure.
AI Analysis
Technical Summary
In August 2026, APT36 initiated Operation RapidRust targeting South Asian government and defense sectors. The campaign introduced RUSTYSHADE, a Rust-based backdoor utilizing private GitHub repositories for command-and-control with AES-256-GCM encryption. Additional tools include RUSTYMOVE for USB-based lateral movement to air-gapped systems, PSNATCH and BASHNATCH for exfiltrating files from Windows and Linux hosts respectively. Attackers used typosquatted domains impersonating Indian news outlets to stage malicious PowerShell scripts. Post-compromise activities involved systematic network reconnaissance, credential harvesting, and lateral movement attempts. The operation was conducted exclusively on weekdays between 4:00-11:00 UTC, indicating strong operational security and sustained targeting of government infrastructure in India and Afghanistan.
Potential Impact
The campaign enables persistent unauthorized access to sensitive government and defense networks in India and Afghanistan, facilitating data exfiltration and lateral movement, including into air-gapped environments. The use of encrypted command-and-control channels and custom tools complicates detection and response efforts. The targeting of critical infrastructure and use of operational security measures increase the risk of prolonged espionage and data compromise.
Mitigation Recommendations
No official patches or fixes are applicable as this is a threat actor campaign using custom malware. Defenders should monitor for indicators of compromise such as the listed malicious hashes, typosquatted domains, and PowerShell script activity. Network segmentation, restricting USB device usage, and enhanced monitoring for unusual lateral movement and credential harvesting behaviors are recommended. Awareness of the attacker’s operational timing (weekdays 4:00-11:00 UTC) may assist in focused detection efforts.
Affected Countries
India, Afghanistan, British Indian Ocean Territory
Indicators of Compromise
- hash: 40a75f87f1e52c33df9ca733aaf8ebbb
- hash: aade06ec611d69f1553035f22356ccf4
- hash: ae77f1834ccde53258bc27a779102af2
- hash: f16f507a8ed515663a4f07050cd97a74
- hash: 00aff1a72c5d5635ab36ce2eb370718a7f0557a0
- hash: 00e1cc0fb1355c196c069791a02b4a5f3b57ae94
- hash: 761ccb15af1c3fe6e4365ddf65578966e4c84fc9
- hash: ad4afe86a835bb2f7768862d358ebd8324c05902
- hash: 05bbeea42f481a3dd1b3f670aba481f7c5c8e897ef321d65188317be5a65a4d7
- hash: 52d07b3ef0c5f27d082551d51027de452682e1fbd5bb38a897ea4b31bd387523
- hash: 70fc6cba3c2021889fb4093d0221dc6925818666df25718a630c562cac18da31
- hash: 80fdde0dafa450ae33937ccef752b46666da567926b2f39b37e02e77f9d6a92e
- url: http://indiatodays.org/pv
- url: http://theprints.org/drivefolder
- url: http://theprints.org/gsheets
- url: http://theprints.org/mau
- url: http://theprints.org/msheets
- domain: indiatodays.org
- domain: officialinfo.org
- domain: theprints.org
Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
Description
In August 2026, the Pakistan-nexus threat actor APT36 launched Operation RapidRust, targeting government and defense organizations in India and Afghanistan with an updated arsenal of custom tools. The campaign introduced RUSTYSHADE, a Rust-based backdoor leveraging private GitHub repositories for command-and-control with AES-256-GCM encryption. Additional tools included RUSTYMOVE for USB-based lateral movement to air-gapped networks, PSNATCH and BASHNATCH for file exfiltration from Windows and Linux systems respectively. The attackers registered typosquatted domains impersonating Indian news outlets to stage malicious PowerShell scripts. Post-compromise activities revealed systematic network reconnaissance, credential harvesting, and lateral movement attempts, with operations conducted exclusively on weekdays between 4:00-11:00 UTC, demonstrating disciplined operational security and sustained targeting of South Asian government infrastructure.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In August 2026, APT36 initiated Operation RapidRust targeting South Asian government and defense sectors. The campaign introduced RUSTYSHADE, a Rust-based backdoor utilizing private GitHub repositories for command-and-control with AES-256-GCM encryption. Additional tools include RUSTYMOVE for USB-based lateral movement to air-gapped systems, PSNATCH and BASHNATCH for exfiltrating files from Windows and Linux hosts respectively. Attackers used typosquatted domains impersonating Indian news outlets to stage malicious PowerShell scripts. Post-compromise activities involved systematic network reconnaissance, credential harvesting, and lateral movement attempts. The operation was conducted exclusively on weekdays between 4:00-11:00 UTC, indicating strong operational security and sustained targeting of government infrastructure in India and Afghanistan.
Potential Impact
The campaign enables persistent unauthorized access to sensitive government and defense networks in India and Afghanistan, facilitating data exfiltration and lateral movement, including into air-gapped environments. The use of encrypted command-and-control channels and custom tools complicates detection and response efforts. The targeting of critical infrastructure and use of operational security measures increase the risk of prolonged espionage and data compromise.
Defensive Guidance
No official patches or fixes are applicable as this is a threat actor campaign using custom malware. Defenders should monitor for indicators of compromise such as the listed malicious hashes, typosquatted domains, and PowerShell script activity. Network segmentation, restricting USB device usage, and enhanced monitoring for unusual lateral movement and credential harvesting behaviors are recommended. Awareness of the attacker’s operational timing (weekdays 4:00-11:00 UTC) may assist in focused detection efforts.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and"]
- Adversary
- Operation C-Major
- Pulse Id
- 6aaaca963a639dd0475e8462
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash40a75f87f1e52c33df9ca733aaf8ebbb | — | |
hashaade06ec611d69f1553035f22356ccf4 | — | |
hashae77f1834ccde53258bc27a779102af2 | — | |
hashf16f507a8ed515663a4f07050cd97a74 | — | |
hash00aff1a72c5d5635ab36ce2eb370718a7f0557a0 | — | |
hash00e1cc0fb1355c196c069791a02b4a5f3b57ae94 | — | |
hash761ccb15af1c3fe6e4365ddf65578966e4c84fc9 | — | |
hashad4afe86a835bb2f7768862d358ebd8324c05902 | — | |
hash05bbeea42f481a3dd1b3f670aba481f7c5c8e897ef321d65188317be5a65a4d7 | — | |
hash52d07b3ef0c5f27d082551d51027de452682e1fbd5bb38a897ea4b31bd387523 | — | |
hash70fc6cba3c2021889fb4093d0221dc6925818666df25718a630c562cac18da31 | — | |
hash80fdde0dafa450ae33937ccef752b46666da567926b2f39b37e02e77f9d6a92e | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://indiatodays.org/pv | — | |
urlhttp://theprints.org/drivefolder | — | |
urlhttp://theprints.org/gsheets | — | |
urlhttp://theprints.org/mau | — | |
urlhttp://theprints.org/msheets | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainindiatodays.org | — | |
domainofficialinfo.org | — | |
domaintheprints.org | — |
Threat ID: 6aabc19155bf5e2cf5372277
Added to database: 09/17/2026, 10:31:45 UTC
Last enriched: 09/17/2026, 10:48:15 UTC
Last updated: 09/17/2026, 22:53:07 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.