Operation RapidRust APT36 Deploys New Malware Tools
Operation RapidRust: APT36 Deploys New Malware Tools π
In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign weβre tracking as Operation RapidRust. APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan.
During our investigation, ThreatLabz discovered new malware families and post-compromise tools, as well as significant post-compromise activity. The new tools include the RUSTYSHADE backdoor, the RUSTYMOVE post-compromise tool, and the PSNATCH and BASHNATCH file-stealing tools. Additionally, APT36 registered multiple typosquatted domains that impersonate popular Indian news outlets to stage malicious PowerShell scripts and payloads.
Key Findings π
- RUSTYSHADE: A new Rust-based backdoor that abuses attacker-controlled private GitHub repositories for command-and-control (C2) and uses AES-256-GCM to encrypt C2 communications. This 64-bit Windows backdoor was deployed on compromised systems using a PowerShell command to download
DriverInstaller.zip. - PSNATCH: A PowerShell-based file stealer that collects files from infected machines and exfiltrates them to the threat actorβs private GitHub repositories. It scans directories like
Desktop,Downloads, andDocumentsfor files modified within the last 120 days. - BASHNATCH: The Linux variant of PSNATCH, targeting Linux environments with similar functionality.
- RUSTYMOVE: A lightweight 64-bit Windows USB propagation tool that monitors for external removable media and copies malicious files to detected drives.
ThreatLabz assesses with high confidence that RUSTYMOVE enables the malware to spread to air-gapped networks. APT36 deployed RUSTYMOVE on a compromised machine using a scheduled task named StandAloneOneDriveUpdater-2626, which launches RUSTYMOVE when a user logs on.
For more detailed information, you can read the full article here: Read full article\n