THREAT OPS › Threat News › Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
IntroductionIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and def
Attributed threat actors
- Transparent TribeG0134
MITRE ATT&CK techniques
Indicators of compromise
- https://f005.backblazeb2.com/file/Clients-easy/DriverInstaller.zipurl
- https://clients-easy.s3.us-east-005.backblazeb2.com/Automata-20.zipurl
- http://ip-api.com/jsonurl
- https://ipinfo.io/jsoncurlurl
- https://ipapi.co/jsonRetrieveurl
- indiatodays.orgdomain
- urltheprints.orgdomain