Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

    Date: 09/17/2026

    Severity: High

    Summary

    Operation RapidRust, an APT36 campaign targeting government and defense organizations in India and Afghanistan, using new tools including RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. RUSTYSHADE is a Rust-based backdoor that uses private GitHub repositories for C2, while RUSTYMOVE enables propagation through removable media. PSNATCH and BASHNATCH perform file collection and exfiltration, including uploads to attacker-controlled GitHub repositories. 

    Indicators of Compromise (IOC) List  

    Domain/URLs

    theprints.org

    officialinfo.org

    indiatodays.org

    theprints.org/adrive

    theprints.org/drivefolder

    theprints.org/mau

    theprints.org/msheets

    theprints.org/gsheets

    https://clients-easy.s3.us-east-005.backblazeb2.com/Automata-20.zip

    https://f005.backblazeb2.com/file/Clients-easy/DriverInstaller.zip

    Hash

    52d07b3ef0c5f27d082551d51027de452682e1fbd5bb38a897ea4b31bd387523

    80fdde0dafa450ae33937ccef752b46666da567926b2f39b37e02e77f9d6a92e

    05bbeea42f481a3dd1b3f670aba481f7c5c8e897ef321d65188317be5a65a4d7

    70fc6cba3c2021889fb4093d0221dc6925818666df25718a630c562cac18da31

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://f005.backblazeb2.com/file/Clients-easy/DriverInstaller.zip" or url like "https://f005.backblazeb2.com/file/Clients-easy/DriverInstaller.zip" or siteurl like "https://f005.backblazeb2.com/file/Clients-easy/DriverInstaller.zip" or domainname like "https://clients-easy.s3.us-east-005.backblazeb2.com/Automata-20.zip" or url like "https://clients-easy.s3.us-east-005.backblazeb2.com/Automata-20.zip" or siteurl like "https://clients-easy.s3.us-east-005.backblazeb2.com/Automata-20.zip" or domainname like "theprints.org" or url like "theprints.org" or siteurl like "theprints.org" or domainname like "officialinfo.org" or url like "officialinfo.org" or siteurl like "officialinfo.org" or domainname like "indiatodays.org" or url like "indiatodays.org" or siteurl like "indiatodays.org"

    Detection Query 2 :

    sha256hash IN ("70fc6cba3c2021889fb4093d0221dc6925818666df25718a630c562cac18da31","80fdde0dafa450ae33937ccef752b46666da567926b2f39b37e02e77f9d6a92e","05bbeea42f481a3dd1b3f670aba481f7c5c8e897ef321d65188317be5a65a4d7","52d07b3ef0c5f27d082551d51027de452682e1fbd5bb38a897ea4b31bd387523")

    Reference: 

    https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and     


    Tags

    MalwareAPT36IndiaAfghanistanRust MalwareBackdoorGitHubExfiltration

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags