Pakistan-Linked Hacking Group Uses GitHub to Control New Backdoor Targeting Government Agencies
Security researchers at Zscaler ThreatLabz have uncovered a new campaign, dubbed Operation RapidRust, run by the Pakistan-aligned hacking group Transparent Tribe (also known as APT36 or Earth Karkaddan). The group is targeting government and defence organisations in India and Afghanistan using four previously undocumented tools: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. This follows a separate campaign identified last month involving another backdoor called PATCHCORD, aimed at Afghan telecom providers and South Asian infrastructure organisations.
A key feature of this campaign is the attackers' use of private GitHub repositories to send and receive commands from infected machines, a technique that helps disguise malicious traffic as normal developer activity. The group has also registered fake domains that mimic well-known Indian news outlets, such as The Print and India Today, to distribute malicious scripts. Of the four new tools, RUSTYSHADE is a backdoor capable of taking screenshots, capturing webcam images, and running background commands, while the other tools are used for moving between systems and stealing files from both Windows and Linux machines.
This activity shows Transparent Tribe continuing to refine its methods, adopting newer programming languages like Rust and legitimate cloud services like GitHub to blend in with normal network traffic and evade detection.