Post

Operation RapidRust APT36 Deploys New Malware Tools

Operation RapidRust APT36 Deploys New Malware Tools

Operation RapidRust: APT36 Deploys New Malware Tools πŸš€

In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan.

During our investigation, ThreatLabz discovered new malware families and post-compromise tools, as well as significant post-compromise activity. The new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools. Additionally, APT36 registered multiple typosquatted domains that impersonate popular Indian news outlets to stage malicious PowerShell scripts and payloads.

Key Findings πŸ”

  • RUSTYSHADE: A new Rust-based backdoor that abuses attacker-controlled private GitHub repositories for command-and-control (C2) and uses AES-256-GCM to encrypt C2 communications. This 64-bit Windows backdoor was deployed on compromised systems using a PowerShell command to download DriverInstaller.zip.
  • PSNATCH: A PowerShell-based file stealer that collects files from infected machines and exfiltrates them to the threat actor’s private GitHub repositories. It scans directories like Desktop, Downloads, and Documents for files modified within the last 120 days.
  • BASHNATCH: The Linux variant of PSNATCH, targeting Linux environments with similar functionality.
  • RUSTYMOVE: A lightweight 64-bit Windows USB propagation tool that monitors for external removable media and copies malicious files to detected drives.

ThreatLabz assesses with high confidence that RUSTYMOVE enables the malware to spread to air-gapped networks. APT36 deployed RUSTYMOVE on a compromised machine using a scheduled task named StandAloneOneDriveUpdater-2626, which launches RUSTYMOVE when a user logs on.

For more detailed information, you can read the full article here: Read full article\n

This post is licensed under CC BY 4.0 by the author.