The Pakistan-aligned group Transparent Tribe (APT36, Earth Karkaddan) has been attributed by Zscaler ThreatLabz to a fresh campaign against government and defence entities in India and Afghanistan, using four previously undocumented tools: RUSTYSHADE, a Rust-based backdoor that reads and writes files in attacker-controlled private GitHub repositories for encrypted command-and-control over the GitHub REST API; RUSTYMOVE, a lateral-movement utility; and the Windows and Linux file-stealers PSNATCH and BASHNATCH. Delivery leans on typosquatted domains impersonating Indian news brands — theprints[.]org for theprint[.]in and indiatodays[.]org for indiatoday[.]in — hosting malicious PowerShell. RUSTYSHADE shares functionality with GITSHELLPAD, the Golang implant used in the September 2025 Gopher Strike campaign, and the disclosure lands a month after Acronis Threat Research Unit tied APT36 to the PATCHCORD backdoor campaign against Afghan telecoms.
| Attribute | Detail |
|---|---|
| Sector | Defence |
| Date | 2026-09-19 |
| Source | The Hacker News |
| Reliability | Tier 2 |