RUSTYMOVE is a lightweight 64-bit Windows removable-media propagation utility written in Rust and associated with Pakistan-linked Transparent Tribe (APT36) activity in Operation RapidRust. It continuously monitors USB, SD, MMC, IEEE 1394, and other removable devices, then copies a staged RUSTYSHADE backdoor archive and a PDF-themed malicious shortcut to newly detected drives. The shortcut is assessed to execute the backdoor following extraction when opened. RUSTYMOVE records removable-drive identifiers to avoid repeatedly staging payloads on the same device. It has no built-in command-and-control channel, reflecting its specialized role in spreading follow-on malware through removable media, including into disconnected or air-gapped environments. APT36 established its execution at user logon through scheduled-task persistence masquerading as an updater. The tool was used against government and defense targets in India and Afghanistan.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RUSTYMOVE is a USB propagation tool for Windows that spreads RUSTYSHADE via USB drives.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows USB-propagation tool used to spread the RUSTYSHADE backdoor through removable drives.
A Rust-based Windows removable-media propagation utility. It monitors for external drives and copies a ZIP containing RUSTYSHADE and a malicious LNK file intended to execute RUSTYSHADE after extraction.
Tool used to propagate the Operation RapidRust infection through removable media.
A Rust-based Windows removable-media propagation utility. It detects newly attached removable drives and copies a RUSTYSHADE-containing archive plus a PDF-disguised shortcut to the drive root, enabling malware transfer into disconnected or air-gapped environments. It maintains a per-drive identifier to avoid repeated copying and is launched through a logon-triggered scheduled task named StandAloneOneDriveUpdater-2626.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.