Transparent Tribe, the Pakistan-aligned group also tracked as APT36, has kept up a heavy tempo against government and defense targets in India and Afghanistan, and its newest toolkit is built around GitHub as infrastructure.
Zscaler ThreatLabz documented the campaign as Operation RapidRust and named four previously unseen tools: RUSTYSHADE, RUSTYMOVE, PSNATCH and BASHNATCH. RUSTYSHADE is the backdoor. It uses attacker-controlled private GitHub repositories for encrypted command and control, writing command, results, heartbeat and screenshot files through the GitHub REST API and reading the output back.
Operators let it take screenshots, capture a webcam photo, move files and run commands in the background. Nearly all observed activity fell between August 20 and September 1, with commands issued only from 4 a.m. to 11 a.m. UTC on weekdays.
Cleanup is not the point. PSNATCH hunts Office documents, archives, media, scripts and databases modified in the previous three months and uploads them to a repository named after the infected machine, capped at 1 GB per file and 5 GB per run. A Linux counterpart, BASHNATCH, does the same work in bash. RUSTYMOVE watches for removable drives and copies DriverInstaller.zip plus a PDF-lookalike LNK onto every USB stick it finds.
The group also registered lookalike domains impersonating Indian outlets, theprints.org and indiatodays.org, to host malicious PowerShell. Blocking those names and flagging GitHub API traffic from endpoints with no business using it are the fastest detections. The operation follows the PATCHCORD backdoor campaign against Afghan telecoms reported in August.
