A cyber threat actor linked to Pakistan has launched a new campaign targeting government and defense organizations in India and Afghanistan This article explores rustyshade malicious. . The operation, dubbed Operation RapidRust, was identified by Zscaler ThreatLabz in August 2026 and demonstrates the group’s continued evolution in malware and post-compromise techniques.
The campaign utilizes several newly discovered tools, including the RUSTYSHADE backdoor, RUSTYMOVE USB propagation malware, and PSNATCH and BASHNATCH file stealers. It employs cloud services, fake news domains, PowerShell scripts, removable media, and scheduled tasks to maintain access and steal sensitive information. The group specializes in gathering intelligence, traversing internal networks, and accessing systems without direct internet connectivity.
It leverages an attacker-controlled private GitHub repository as its command-and-control channel, enabling operators to issue commands and retrieve stolen data through the GitHub REST API. Operators of APT36 can use RUSTYSHADE to gather system details, list files and drives, run commands, capture screenshots, take webcam photos, and download selected files. When it detects an external drive, RUSTYMOVE copies two pre-staged files to the device’s root directory: a ZIP archive containing RUSTYSHADE and a malicious shortcut file disguised as a PDF document.
Indicators of Compromise Filename MD5 SHA-1 SHA-256 Description DriverInstaller.zip 40a75f87f1e52c33df9ca733aaf8ebbb 00aff1a72c5d5635ab36ce2eb370718a7f0557a0 52d07b3ef0c5f27d082551d51027de452682e1fbd5bb38a897ea4b31bd387523 ZIP archive containing RUSTYSHADE DriverInstaller.exe ae77f1834ccde53258bc27a779102af2 761ccb15af1c3fe6e4365ddf65 Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort.












