Transparent Tribe Operation RapidRust campaign targeting India and Afghanistan
Campaign
Summary
Hide ▲
Show ▼
The Transparent Tribe operation Operation RapidRust is sustaining active cyber attacks against government and defense organizations in India and Afghanistan, raising the risk of follow-on intrusion and credential theft. The group is using newly identified tools RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH to support command-and-control, exfiltration, and USB propagation. It is also abusing private GitHub repositories and typosquatted domains impersonating The Print and India Today to host malicious content. Much of the observed activity fell between August 20 and September 1, 2026, with command activity limited to weekday mornings UTC.
Related Happenings
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
SideCopy Operation XENOFISCAL spear-phishing campaign targeting Afghan finance entities
Campaign
H score25
First: 02.06.2026 12:05
Last: 02.06.2026 12:05
Sources 1
About this happening:
The SideCopy-linked Operation XENOFISCAL spear-phishing campaign is targeting Afghanistan's Ministry of Finance and related provincial finance offices with Xeno RAT*...
SideCopy Operation XENOFISCAL spear-phishing campaign targeting Afghan finance entities
CampaignAbout this happening: The SideCopy-linked Operation XENOFISCAL spear-phishing campaign is targeting Afghanistan's Ministry of Finance and related provincial finance offices with Xeno RAT*...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Transparent Tribe AI-assisted implant campaign targeting India
Campaign
H score32
First: 06.03.2026 17:11
Last: 06.03.2026 17:11
Sources 1
About this happening:
Transparent Tribe (APT36) is running an evolving campaign that now includes PATCHCORD and SHEETCORD alongside earlier AI-assisted implants. The newer activity targ...
Transparent Tribe AI-assisted implant campaign targeting India
CampaignAbout this happening: Transparent Tribe (APT36) is running an evolving campaign that now includes PATCHCORD and SHEETCORD alongside earlier AI-assisted implants. The newer activity targ...
Latest development: 13.08.2026 18:00
Transparent Tribe, assessed with moderate confidence as APT36, is targeting Afghan telecom providers, Indian government IT networks, and South Asian critical infrastructure with PATCHCORD and SHEETCORD. The implants are delivered through fake Afghan Telecom lures, Telecom_TMS.zip, and nic-support[.]site, then use browser-shortcut hijacking or the Windows Startup folder for persistence, Google Sheets or GitHub Gists for C2, and infrastructure tied to CVE-2024-6387 exploit material.
Dust Specter Iraq Foreign Affairs AI impersonation campaign
Campaign
H score33
First: 03.03.2026 12:30
Last: 03.03.2026 12:30
Sources 1
About this happening:
Dust Specter targeted Iraqi government officials in a January 2026 campaign that used impersonation, AI tools, and compromised infrastructure to deliver malici...
Dust Specter Iraq Foreign Affairs AI impersonation campaign
CampaignAbout this happening: Dust Specter targeted Iraqi government officials in a January 2026 campaign that used impersonation, AI tools, and compromised infrastructure to deliver malici...
Timeline
-
18.09.2026 18:24 2 articles · 1h ago
Transparent Tribe attributed to Operation RapidRust attacks in India and Afghanistan
Initial DisclosureZscaler ThreatLabz attributes Transparent Tribe (APT36/Earth Karkaddan) to Operation RapidRust, a campaign targeting government and defense entities in India and Afghanistan with the newly identified tools RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity uses private GitHub repositories for encrypted command-and-control, attacker-controlled GitHub gist content for file stealing, and typosquatted domains such as theprints[.]org and indiatodays[.]org to host malicious PowerShell scripts and payloads; much of the observed activity fell between August 20 and September 1, 2026, with C2 commands issued only between 4 a.m. and 11 a.m. UTC on weekdays.
Show sources
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 — thehackernews.com — 18.09.2026 18:24
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 — thehackernews.com — 18.09.2026 18:24