Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Transparent Tribe Unveils Advanced Rust-Based Backdoor, Exploiting Private GitHub Repositories for Command and Control




Transparent Tribe, a Pakistan-aligned threat group, has recently deployed a new Rust-based backdoor known as RUSTYSHADE, leveraging private GitHub repositories for command and control. The backdoor is part of the Operation RapidRust campaign, which targets government and defense entities in India and Afghanistan. The group's sophisticated tactics and techniques underscore the evolving nature of cyber threats, emphasizing the need for proactive measures to protect against emerging threats.

  • Threat actor Transparent Tribe (APT36, Earth Karkaddan) has deployed a sophisticated Rust-based backdoor called RUSTYSHADE.
  • RUSTYSHADE utilizes private GitHub repositories for encrypted command-and-control communications.
  • The backdoor is composed of four malware families, including a backdoor, lateral movement utility, and two file-stealing programs.
  • RUSTYSHADE has parsing and writing capabilities, allowing it to execute various malicious operations.
  • The threat actor is targeting government and defense entities in India and Afghanistan with Operation RapidRust.
  • The group's post-compromise activity involves system, user, and network reconnaissance, followed by next-stage payload deployment.
  • The RUSTYSHADE deployment highlights the evolving nature of cyber threats and the need for proactive measures to protect against emerging threats.



  • The cybersecurity landscape has witnessed a significant evolution in the tactics, techniques, and procedures (TTPs) employed by threat actors, with the latest development pointing towards the emergence of a sophisticated Rust-based backdoor known as RUSTYSHADE. This cutting-edge backdoor has been attributed to the Pakistan-aligned threat group, Transparent Tribe, also tracked as APT36 and Earth Karkaddan. The group has been observed to be targeting government and defense entities in India and Afghanistan, with the recent Operation RapidRust campaign marking a notable escalation in their cyber espionage activities.

    According to a technical report published by Zscaler ThreatLabz, the malware in question utilizes private GitHub repositories for encrypted command-and-control (C2) communications, leveraging a peculiar approach that allows the attackers to maintain a high level of control and anonymity. This tactic is eerily reminiscent of another notorious threat actor, GITSHELLPAD, a Golang implant that was observed in September 2025 in connection with a campaign known as Gopher Strike.

    The RUSTYSHADE backdoor is distinguished by its use of four newly identified malware families, including one that serves as a backdoor, another that functions as a lateral movement utility, and the remaining two as file-stealing programs designed for Windows and Linux systems. The backdoor, RUSTYSHADE, is particularly noteworthy for its parsing and writing capabilities in the private GitHub repository for bidirectional communication using the GitHub REST API. This allows the attackers to execute various malicious operations, including screenshot capture, webcam photo capture, file operations, and background command execution.

    Furthermore, the threat actor has been observed fetching a file stealer from an attacker-controlled GitHub gist that comes in two variants for targeting both Windows and Linux environments. The file collection is limited to 1 GB per file and 5 GB per execution, underscoring the group's emphasis on stealth and precision in their operations.

    The operations associated with Operation RapidRust are indicative of a highly organized and efficient threat actor. Post-compromise activity from APT36 operators involves system, user, and network reconnaissance, followed by the deployment of next-stage payloads. A significant portion of the actions took place between August 20 and September 1, 2026, with the C2 commands issued only between 4 a.m. and 11 a.m. UTC and only on weekdays.

    The recent deployment of RUSTYSHADE by Transparent Tribe highlights the evolving nature of cyber threats and the importance of staying vigilant in the face of emerging threats. As the threat landscape continues to evolve, it is essential for organizations to adopt proactive measures to protect themselves against such sophisticated backdoors.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Transparent-Tribe-Unveils-Advanced-Rust-Based-Backdoor-Exploiting-Private-GitHub-Repositories-for-Command-and-Control-ehn.shtml

  • https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html


  • Published: Fri Sep 18 11:29:49 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us