Interestana
Home/News/Transparent Tribe Uses Rust Backdoor via Private GitHub
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Transparent Tribe Uses Rust Backdoor via Private GitHub

Transparent Tribe Uses Rust Backdoor via Private GitHub

The Pakistan-aligned threat group known as Transparent Tribe, also identified as APT36 and Earth Karkaddan, has been linked to a new wave of cyberattacks targeting government and defense organizations in India and Afghanistan. These recent activities, detailed by Zscaler ThreatLabz, involve the deployment of previously undocumented tools. The newly identified malware includes RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH, all of which are written in the Rust programming language. This operation has been codenamed Operation "Dark Connection" by researchers.

Transparent Tribe's modus operandi in this campaign involves exploiting private GitHub repositories to establish command and control (C2) infrastructure. This technique allows the attackers to maintain stealth and evade detection by blending their malicious traffic with legitimate developer activity. The group has a history of targeting entities within India, with a particular focus on government, defense, and academic sectors. Their previous campaigns have utilized various sophisticated techniques, including spear-phishing and custom malware.

The newly discovered tools, RUSTYSHADE and RUSTYMOVE, function as backdoors, providing Transparent Tribe with persistent access to compromised systems. RUSTYSHADE is capable of executing commands remotely, exfiltrating data, and downloading additional payloads. RUSTYMOVE appears to be involved in file manipulation and movement within the compromised network, potentially for lateral movement or data staging. PSNATCH and BASHNATCH are designed for credential theft, with PSNATCH targeting Windows systems and BASHNATCH focusing on Linux environments. These tools collectively enable the threat group to conduct espionage, data theft, and potentially further disruptive actions against the targeted entities.

Zscaler ThreatLabz observed that the threat actors are using legitimate GitHub repositories, but are creating private ones to host their malicious code and communicate with the infected machines. This method of using cloud-based services for C2 is a growing trend among advanced persistent threat (APT) groups, as it offers a degree of obfuscation and can be harder for security solutions to block without impacting legitimate business operations. The use of Rust for developing these tools is also notable, as Rust offers benefits like memory safety and performance, which can lead to more robust and efficient malware. The group's continued focus on government and defense targets underscores the ongoing cyber threats faced by these critical sectors in the region.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next