Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-19 · updated: 2026-09-19 · tags: [incident, defence] · confidence: high · severity: medium · affected_sectors: [defence] · au_impact: true

The Pakistan-aligned group Transparent Tribe (APT36, Earth Karkaddan) has been attributed by Zscaler ThreatLabz to a fresh campaign against government and defence entities in India and Afghanistan, using four previously undocumented tools: RUSTYSHADE, a Rust-based backdoor that reads and writes files in attacker-controlled private GitHub repositories for encrypted command-and-control over the GitHub REST API; RUSTYMOVE, a lateral-movement utility; and the Windows and Linux file-stealers PSNATCH and BASHNATCH. Delivery leans on typosquatted domains impersonating Indian news brands — theprints[.]org for theprint[.]in and indiatodays[.]org for indiatoday[.]in — hosting malicious PowerShell. RUSTYSHADE shares functionality with GITSHELLPAD, the Golang implant used in the September 2025 Gopher Strike campaign, and the disclosure lands a month after Acronis Threat Research Unit tied APT36 to the PATCHCORD backdoor campaign against Afghan telecoms.

Attribute Detail
Sector Defence
Date 2026-09-19
Source The Hacker News
Reliability Tier 2