Threat Intelligence

Pakistan-Linked Hacking Group Uses GitHub to Control New Backdoor Targeting Government Agencies

The Hacker News · 19 Sept 2026
Key Takeaway Australian organisations, especially those with government, defence, or international supply chain links, should monitor for unusual outbound traffic to code-hosting platforms like GitHub and train staff to be wary of links from unfamiliar or lookalike news domains.

Security researchers at Zscaler ThreatLabz have uncovered a new campaign, dubbed Operation RapidRust, run by the Pakistan-aligned hacking group Transparent Tribe (also known as APT36 or Earth Karkaddan). The group is targeting government and defence organisations in India and Afghanistan using four previously undocumented tools: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. This follows a separate campaign identified last month involving another backdoor called PATCHCORD, aimed at Afghan telecom providers and South Asian infrastructure organisations.

A key feature of this campaign is the attackers' use of private GitHub repositories to send and receive commands from infected machines, a technique that helps disguise malicious traffic as normal developer activity. The group has also registered fake domains that mimic well-known Indian news outlets, such as The Print and India Today, to distribute malicious scripts. Of the four new tools, RUSTYSHADE is a backdoor capable of taking screenshots, capturing webcam images, and running background commands, while the other tools are used for moving between systems and stealing files from both Windows and Linux machines.

This activity shows Transparent Tribe continuing to refine its methods, adopting newer programming languages like Rust and legitimate cloud services like GitHub to blend in with normal network traffic and evade detection.

APT36 Transparent Tribe Malware GitHub C2 Government Security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.