Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

Summary

The Pakistan-aligned threat group Transparent Tribe (APT36) is reportedly deploying new backdoor tools, RUSTYSHADE and RUSTYMOVE, in cyber attacks targeting Indian and Afghan government and defense entities. The group is leveraging private GitHub repositories for command and control (C2) communications with these newly developed Rust-based tools, along with PSNATCH and BASHNATCH.

IFF Assessment

FOE

This activity represents a new offensive capability deployed by a known threat actor, posing a direct risk to targeted organizations and indicating an escalating threat landscape.

Defender Context

Defenders should be aware of Transparent Tribe's evolving tactics, particularly their use of Rust-based malware and private GitHub repositories for C2. Monitoring for the indicators of compromise associated with RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH is crucial for early detection and response.

Read Full Story →