In a recent campaign tracked as Operation RapidRust, the Pakistan-nexus threat actor APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. APT36 has deployed new malware families and post-compromise tools, including RUSTYSHADE, a 64-bit Windows backdoor written in Rust that abuses attacker-controlled private GitHub repositories for C2 communication. The threat actor uses AES-256-GCM to encrypt C2 messages and employs a command tasking mechanism to synchronize the communication between infected machines and the C2 server.
RUSTYSHADE is designed to read and write specific filenames in the private GitHub repository, including encrypted C2 commands, results, system reconnaissance data, heartbeat beacons, and exfiltrated file contents. The threat actor issues commands and receives resulting output in the GitHub repository. RUSTYSHADE also uses a base64-encoding mechanism to encrypt and decrypt messages. Furthermore, APT36 has deployed PSNATCH, a PowerShell-based file-stealing tool that scans pre-configured directories and exfiltrates files matching specific extensions to the threat actor's private GitHub repositories.[/subscribe_to_unlock_form]
In a recent campaign tracked as Operation RapidRust, the Pakistan-nexus threat actor APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. APT36 has deployed new malware families and post-compromise tools, including RUSTYSHADE, a 64-bit Windows backdoor written in Rust that abuses attacker-controlled private GitHub repositories for C2 communication. The threat actor uses AES-256-GCM to encrypt C2 messages and employs a command tasking mechanism to synchronize the communication between infected machines and the C2 server.
RUSTYSHADE is designed to read and write specific filenames in the private GitHub repository, including encrypted C2 commands, results, system reconnaissance data, heartbeat beacons, and exfiltrated file contents. The threat actor issues commands and receives resulting output in the GitHub repository. RUSTYSHADE also uses a base64-encoding mechanism to encrypt and decrypt messages. Furthermore, APT36 has deployed PSNATCH, a PowerShell-based file-stealing tool that scans pre-configured directories and exfiltrates files matching specific extensions to the threat actor's private GitHub repositories.[emaillocker id="1283"]
The significance of this campaign lies in its high operational tempo and updated TTPs by APT36. The threat actor's use of Rust-based backdoors and post-compromise tools demonstrates their adaptability and willingness to evolve their tactics. This campaign highlights the need for defenders to remain vigilant and update their security measures accordingly. The targeted sectors, including government and defense organizations in India and Afghanistan, must be aware of these threats and take necessary precautions to prevent lateral movement and data exfiltration.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1573.001 | Encrypted Channel | Symmetric Cryptography |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Discovery | E1083 | File and Directory Discovery |
| Exfiltration | E1020 | Automated Exfiltration |
| Cryptography Micro-objective | C0027 | Encrypt Data |
| Discovery | E1082 | System Information Discovery |
| Execution | E1204 | User Execution |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
The following reports contain further technical details:
[/emaillocker]