Find notable cyber news and cases, enriched with sources, timelines, and signals.

Transparent Tribe Operation RapidRust campaign targeting India and Afghanistan

Campaign
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

The Transparent Tribe operation Operation RapidRust is sustaining active cyber attacks against government and defense organizations in India and Afghanistan, raising the risk of follow-on intrusion and credential theft. The group is using newly identified tools RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH to support command-and-control, exfiltration, and USB propagation. It is also abusing private GitHub repositories and typosquatted domains impersonating The Print and India Today to host malicious content. Much of the observed activity fell between August 20 and September 1, 2026, with command activity limited to weekday mornings UTC.

Related Happenings

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

SideCopy Operation XENOFISCAL spear-phishing campaign targeting Afghan finance entities

Campaign
H score25 First: 02.06.2026 12:05 Last: 02.06.2026 12:05 Sources 1

About this happening: The SideCopy-linked Operation XENOFISCAL spear-phishing campaign is targeting Afghanistan's Ministry of Finance and related provincial finance offices with Xeno RAT*...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

Transparent Tribe AI-assisted implant campaign targeting India

Campaign
H score32 First: 06.03.2026 17:11 Last: 06.03.2026 17:11 Sources 1

About this happening: Transparent Tribe (APT36) is running an evolving campaign that now includes PATCHCORD and SHEETCORD alongside earlier AI-assisted implants. The newer activity targ...

Latest development: 13.08.2026 18:00

Transparent Tribe, assessed with moderate confidence as APT36, is targeting Afghan telecom providers, Indian government IT networks, and South Asian critical infrastructure with PATCHCORD and SHEETCORD. The implants are delivered through fake Afghan Telecom lures, Telecom_TMS.zip, and nic-support[.]site, then use browser-shortcut hijacking or the Windows Startup folder for persistence, Google Sheets or GitHub Gists for C2, and infrastructure tied to CVE-2024-6387 exploit material.

Dust Specter Iraq Foreign Affairs AI impersonation campaign

Campaign
H score33 First: 03.03.2026 12:30 Last: 03.03.2026 12:30 Sources 1

About this happening: Dust Specter targeted Iraqi government officials in a January 2026 campaign that used impersonation, AI tools, and compromised infrastructure to deliver malici...

Timeline

  1. 18.09.2026 18:24 2 articles · 1h ago

    Transparent Tribe attributed to Operation RapidRust attacks in India and Afghanistan

    Initial Disclosure

    Zscaler ThreatLabz attributes Transparent Tribe (APT36/Earth Karkaddan) to Operation RapidRust, a campaign targeting government and defense entities in India and Afghanistan with the newly identified tools RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity uses private GitHub repositories for encrypted command-and-control, attacker-controlled GitHub gist content for file stealing, and typosquatted domains such as theprints[.]org and indiatodays[.]org to host malicious PowerShell scripts and payloads; much of the observed activity fell between August 20 and September 1, 2026, with C2 commands issued only between 4 a.m. and 11 a.m. UTC on weekdays.

    Show sources