Skip to content
TodayPrism
Updated 2h agoTech & Cyber

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories

Headline by Prism · from 1 report

The threat group Transparent Tribe is using new Rust-based malware and private GitHub repositories for C2 in attacks against government and defense targets.

1 outlet · 1 report · EnglishOne source so far

The record

Written from the 1 report below. Nothing here is unsourced.

  • The threat group known as Transparent Tribe, or APT36, is conducting a new campaign called Operation RapidRust against government and defense organizations in India and Afghanistan.
  • The attackers are using previously undocumented malware, including a Rust-based backdoor that leverages private GitHub repositories for command-and-control operations.
  • They are also utilizing typosquatted domains to impersonate Indian news outlets to distribute malicious payloads.
  • The group employs specialized tools for file theft, lateral movement, and system reconnaissance.

What to watch next

  • Further expansion of the group's use of GitHub for C2 infrastructure.
  • Monitoring of the typosquatted news domains by affected organizations.
  • Potential adoption of similar Rust-based malware by other threat actors.

Who said what1

Only words found exactly in the article are shown, attributed and linked to the line they came from.

Sudeep Singh

1 quote · 1 outlet

  • APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan
    [1]The Hacker News2h agoOpen at the quote ↗
    In the article

    India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation RapidRust. " APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan ," Sudeep Singh, senior manager of APT Research at Zscaler ThreatLabz, said in a technical report published this week. The discovery comes a little over a month after Acronis Threat Research Unit (TRU) tied the

Coverage1

1 report
English national1

All filed from India

Named India · Afghanistan · India Today · The Print · Acronis Threat Research Unit · GitHub · Sudeep Singh · Transparent Tribe · Zscaler ThreatLabz

Ask this story

Answers cite the reports above, or say they can't.

← Today’s record

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories | Prism