Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
Pakistan-aligned threat group Transparent Tribe deploys new Rust backdoor in cyber attacks targeting Indian and Afghan entities. Uses private GitHub repositories for C2 and mimics popular news sites for malicious scripts.
Intelligence analysis by Qwen 2.5 (3B)

Pakistan-aligned threat group Transparent Tribe deploys a new Rust-based backdoor in cyber attacks targeting Indian and Afghan entities. The backdoor uses private GitHub repositories for C2 and mimics popular news sites for malicious scripts.
A group of bad guys from Pakistan is using a new kind of computer trick to spy on Indian and Afghan governments. They're using secret websites and fake news sites to hide their tricks and send bad stuff to computers.
Analysis
{"heading_1":"Operation RapidRust","subheading_1":"Background","content_1":"The Pakistan-aligned threat group Transparent Tribe has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH.","subheading_2":"Tactics, Techniques, and Procedures (TTPs)","content_2":"The threat group has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. The attacks use private GitHub repositories for command-and-control (C2) and register typosquatted domains to host malicious PowerShell scripts and payloads.","subheading_3":"Malware Families","content_3":"The campaign involves four newly identified malware families: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. RUSTYSHADE is a Rust-based backdoor that uses attacker-controlled private GitHub repositories for encrypted C2 communications. PSNATCH and BASHNATCH are PowerShell and bash script file-stealing programs, respectively.","subheading_4":"Post-Compromise Activity","content_4":"Post-compromise activity involves fetching a file stealer from an attacker-controlled GitHub gist for Windows and Linux environments. The file collection is limited to 1 GB per file and 5 GB per execution. The threat actor also deploys next-stage payloads and engages in system, user, and network reconnaissance.","subheading_5":"Timeline and Frequency","content_5":"The campaign took place between August 20 and September 1, 2026, with C2 commands issued only between 4 a.m. and 11 a.m. UTC and only on weekdays. The threat group continues to target government and defense entities in India and Afghanistan while maintaining high operational tempo and evolving TTPs."}
Key points
- Transparent Tribe deploys a new Rust-based backdoor in cyber attacks targeting Indian and Afghan entities.
- The backdoor uses private GitHub repositories for C2 and mimics popular news sites for malicious scripts.
- The threat group continues to target government and defense organizations in India and Afghanistan.
- The campaign involves four newly identified malware families: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH.
- The threat actor deploys next-stage payloads and engages in system, user, and network reconnaissance.
This shows that even with new tools, the bad guys are still trying to do the same things they've always done. It's important to keep our computers safe and check for any strange things.
If the bad guys find out about these new tricks, they might use them to do even more damage. It's important for everyone to stay alert and be careful with their computers.


