RUSTYSHADE is a 64-bit Windows backdoor written in Rust and attributed to Pakistan-aligned Transparent Tribe, also tracked as APT36, in Operation RapidRust. It targeted government and defense organizations in India and Afghanistan. The implant abuses attacker-controlled private GitHub repositories and the GitHub REST API for encrypted command-and-control, beaconing, reconnaissance reporting, command-result retrieval, and storage of stolen data. Its communications use AES-256-GCM encryption derived from an embedded GitHub authentication token. RUSTYSHADE can execute shell commands and detached processes, enumerate drives and directories, capture desktop screenshots and webcam images, and compress, encrypt, and upload selected files. It was deployed alongside RUSTYMOVE, a removable-media propagation utility that placed a RUSTYSHADE archive and a malicious shortcut on external drives, facilitating propagation into disconnected or air-gapped environments. The campaign also used lookalike media sites and cloud-hosted payload staging infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RUSTYSHADE is a Rust-based backdoor using private GitHub repositories for command and control (C2).
23 distinct techniques documented for this family, organized by ATT&CK tactic.
APT36 swept 192.168.1.1 through 192.168.1.254 using ping and PowerShell Test-Connection, and used nbtstat and net view to identify network hosts.
info.txt [is used] to store system reconnaissance data ... Post-compromise activity from APT36 operators involves system, user, and network reconnaissance.
The toolkit can steal documents... PSNATCH limits collection by file size and tracks previously uploaded material.
RUSTYSHADE, a Rust-based backdoor using private GitHub repositories for command and control (C2)... RUSTYSHADE communicates via specific files within GitHub repositories, storing encrypted commands and exfiltrating data.
RUSTYSHADE... uses attacker-controlled private GitHub repositories for commands and stolen data.
RUSTYSHADE uses attacker-controlled private GitHub repositories for encrypted C2 communications, parsing and writing files in a private repository using the GitHub REST API.
RUSTYSHADE communicates via specific files within GitHub repositories, storing encrypted commands and exfiltrating data like screenshots and webcam captures.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based backdoor that uses files in private GitHub repositories for C2, receiving encrypted commands and exfiltrating screenshots and webcam captures.
Rust-based backdoor that uses private GitHub repositories and the GitHub REST API for encrypted bidirectional C2. It supports reconnaissance, background command execution, file operations, screenshot capture, webcam capture, and exfiltration of collected data.
Rust-based backdoor that communicates with attacker-controlled private GitHub repositories for command-and-control.
A 64-bit Rust backdoor distributed by RUSTYMOVE via removable media. It uses private GitHub repositories as command-and-control and exfiltration infrastructure, encrypts communications, and supports directory listing, shell execution, screenshot capture, webcam-image capture, and file upload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.