Threat Advisory

APT36 Deploys RUSTYSHADE Backdoor and File-Stealing Tools

Threat: Malware
Threat Actor Name: APT36
Threat Actor Type: Nation-Sponsored or State-Sponsored
Targeted Region: India, Afghanistan, Pakistan
Alias: Mythic Leopard, Temp.Lapis, ATK64, Green Havildar, ProjectM, Transparent Tribe, APT-C-56, Copper Fieldstone, STEPPY-KAVACH, Earth Karkaddan
Threat Actor Region: Pakistan
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

In a recent campaign tracked as Operation RapidRust, the Pakistan-nexus threat actor APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. APT36 has deployed new malware families and post-compromise tools, including RUSTYSHADE, a 64-bit Windows backdoor written in Rust that abuses attacker-controlled private GitHub repositories for C2 communication. The threat actor uses AES-256-GCM to encrypt C2 messages and employs a command tasking mechanism to synchronize the communication between infected machines and the C2 server.

RUSTYSHADE is designed to read and write specific filenames in the private GitHub repository, including encrypted C2 commands, results, system reconnaissance data, heartbeat beacons, and exfiltrated file contents. The threat actor issues commands and receives resulting output in the GitHub repository. RUSTYSHADE also uses a base64-encoding mechanism to encrypt and decrypt messages. Furthermore, APT36 has deployed PSNATCH, a PowerShell-based file-stealing tool that scans pre-configured directories and exfiltrates files matching specific extensions to the threat actor's private GitHub repositories.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

In a recent campaign tracked as Operation RapidRust, the Pakistan-nexus threat actor APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. APT36 has deployed new malware families and post-compromise tools, including RUSTYSHADE, a 64-bit Windows backdoor written in Rust that abuses attacker-controlled private GitHub repositories for C2 communication. The threat actor uses AES-256-GCM to encrypt C2 messages and employs a command tasking mechanism to synchronize the communication between infected machines and the C2 server.

RUSTYSHADE is designed to read and write specific filenames in the private GitHub repository, including encrypted C2 commands, results, system reconnaissance data, heartbeat beacons, and exfiltrated file contents. The threat actor issues commands and receives resulting output in the GitHub repository. RUSTYSHADE also uses a base64-encoding mechanism to encrypt and decrypt messages. Furthermore, APT36 has deployed PSNATCH, a PowerShell-based file-stealing tool that scans pre-configured directories and exfiltrates files matching specific extensions to the threat actor's private GitHub repositories.[emaillocker id="1283"]

The significance of this campaign lies in its high operational tempo and updated TTPs by APT36. The threat actor's use of Rust-based backdoors and post-compromise tools demonstrates their adaptability and willingness to evolve their tactics. This campaign highlights the need for defenders to remain vigilant and update their security measures accordingly. The targeted sectors, including government and defense organizations in India and Afghanistan, must be aware of these threats and take necessary precautions to prevent lateral movement and data exfiltration.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1573.001 Encrypted Channel Symmetric Cryptography
Exfiltration T1041 Exfiltration Over C2 Channel -
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Discovery E1083 File and Directory Discovery
Exfiltration E1020 Automated Exfiltration
Cryptography Micro-objective C0027 Encrypt Data
Discovery E1082 System Information Discovery
Execution E1204 User Execution
Persistence F0012 Registry Run Keys / Startup Folder

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu