Skip to main content

Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

0
Medium
Published: 09/16/2026 (09/16/2026, 16:57:58 UTC)
Source: AlienVault OTX General

Description

In August 2026, the Pakistan-nexus threat actor APT36 launched Operation RapidRust, targeting government and defense organizations in India and Afghanistan with an updated arsenal of custom tools. The campaign introduced RUSTYSHADE, a Rust-based backdoor leveraging private GitHub repositories for command-and-control with AES-256-GCM encryption. Additional tools included RUSTYMOVE for USB-based lateral movement to air-gapped networks, PSNATCH and BASHNATCH for file exfiltration from Windows and Linux systems respectively. The attackers registered typosquatted domains impersonating Indian news outlets to stage malicious PowerShell scripts. Post-compromise activities revealed systematic network reconnaissance, credential harvesting, and lateral movement attempts, with operations conducted exclusively on weekdays between 4:00-11:00 UTC, demonstrating disciplined operational security and sustained targeting of South Asian government infrastructure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 10:48:15 UTC

Technical Analysis

In August 2026, APT36 initiated Operation RapidRust targeting South Asian government and defense sectors. The campaign introduced RUSTYSHADE, a Rust-based backdoor utilizing private GitHub repositories for command-and-control with AES-256-GCM encryption. Additional tools include RUSTYMOVE for USB-based lateral movement to air-gapped systems, PSNATCH and BASHNATCH for exfiltrating files from Windows and Linux hosts respectively. Attackers used typosquatted domains impersonating Indian news outlets to stage malicious PowerShell scripts. Post-compromise activities involved systematic network reconnaissance, credential harvesting, and lateral movement attempts. The operation was conducted exclusively on weekdays between 4:00-11:00 UTC, indicating strong operational security and sustained targeting of government infrastructure in India and Afghanistan.

Potential Impact

The campaign enables persistent unauthorized access to sensitive government and defense networks in India and Afghanistan, facilitating data exfiltration and lateral movement, including into air-gapped environments. The use of encrypted command-and-control channels and custom tools complicates detection and response efforts. The targeting of critical infrastructure and use of operational security measures increase the risk of prolonged espionage and data compromise.

Defensive Guidance

No official patches or fixes are applicable as this is a threat actor campaign using custom malware. Defenders should monitor for indicators of compromise such as the listed malicious hashes, typosquatted domains, and PowerShell script activity. Network segmentation, restricting USB device usage, and enhanced monitoring for unusual lateral movement and credential harvesting behaviors are recommended. Awareness of the attacker’s operational timing (weekdays 4:00-11:00 UTC) may assist in focused detection efforts.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and"]
Adversary
Operation C-Major
Pulse Id
6aaaca963a639dd0475e8462

Indicators of Compromise

Hash

ValueDescriptionCopy
hash40a75f87f1e52c33df9ca733aaf8ebbb
hashaade06ec611d69f1553035f22356ccf4
hashae77f1834ccde53258bc27a779102af2
hashf16f507a8ed515663a4f07050cd97a74
hash00aff1a72c5d5635ab36ce2eb370718a7f0557a0
hash00e1cc0fb1355c196c069791a02b4a5f3b57ae94
hash761ccb15af1c3fe6e4365ddf65578966e4c84fc9
hashad4afe86a835bb2f7768862d358ebd8324c05902
hash05bbeea42f481a3dd1b3f670aba481f7c5c8e897ef321d65188317be5a65a4d7
hash52d07b3ef0c5f27d082551d51027de452682e1fbd5bb38a897ea4b31bd387523
hash70fc6cba3c2021889fb4093d0221dc6925818666df25718a630c562cac18da31
hash80fdde0dafa450ae33937ccef752b46666da567926b2f39b37e02e77f9d6a92e

Url

ValueDescriptionCopy
urlhttp://indiatodays.org/pv
urlhttp://theprints.org/drivefolder
urlhttp://theprints.org/gsheets
urlhttp://theprints.org/mau
urlhttp://theprints.org/msheets

Domain

ValueDescriptionCopy
domainindiatodays.org
domainofficialinfo.org
domaintheprints.org

Threat ID: 6aabc19155bf5e2cf5372277

Added to database: 09/17/2026, 10:31:45 UTC

Last enriched: 09/17/2026, 10:48:15 UTC

Last updated: 09/17/2026, 22:53:07 UTC

Views: 74

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses