Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

Executive Summary

The Pakistan‑aligned threat group Transparent Tribe (APT36/Earth Karkaddan) has launched a new campaign targeting Indian and Afghan government and defense entities. Using a Rust‑based backdoor, the group leverages private GitHub repositories for command‑and‑control. Newly documented tools include RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH, as reported by Zscaler ThreatLabz.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-18T15:24:16+00:00 - Category: threat-intel

Original Description: The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation

"We all have problems. The way we solve them is what makes us different."

— Unknown
Source: The Hacker News