KMS Auto was abused as the entry point in a multi-stage intrusion that led to XMRig mining, remote access via ScreenConnect and MeshAgent, and a scareware payload posing as ransomware. #KMSAuto #XMRig #APT36

Explore how the Operation RapidRust APT36 malware campaign by Zscaler ThreatLabz exposes new tools like RUSTYSHADE and RUSTYMOVE targeting governments.
#OperationRapidRust #APT36 #Cybersecurity #ZscalerThreatLabz #Malware
Transparent Tribe launched Operation RapidRust against government and defense targets in India and Afghanistan, using Rust backdoors, private GitHub C2, and new tools for stealthy theft and USB propagation. #India #APT36 #RustBackdoor
APT36 has upgraded to a shiny new Rust backdoor using private GitHub repos for command and control. Same story, different day for security. #rustbackdoor #apt36
APT36’s new RapidRust campaign uses Rust backdoors, GitHub C2, USB spread & media typosquats in India/Afghanistan. #Cybersecurity #APT36 #Rust #OperationRapidRust #GitHubC2 #Malware thedailytechfeed.com/apt36-unveil...
APT36 has deployed a new RustyShade variant, RustyMove, that is targeting Indian and Afghan government systems. #APT36 #RustyShade #RustyMove #India #Afghanistan https://malware.news/t/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and-bashnatch/125646
@zscalerinc.bsky.social
APT36 deployed Rust backdoor, file stealers, and USB propagation tools against Indian and Afghan government targets.
-
IOCs: theprints[.]org, indiatodays[.]org, clients-easy[.]s3[.]us-east-005[.]backblazeb2[.]com
-
#APT36 #Malware #ThreatIntel
APT36’s Operation RapidRust uses USB malware and Rust tools to breach air-gapped government systems. #APT36 #OperationRapidRust #USBMalware #RustTools #AirGapSecurity #CyberEspionage https://thedailytechfeed.com/operation-rapidrust-apt36s-usb-malware-threatens-air-gapped-networks/
APT36's Operation RapidRust targeted India and Afghanistan government and defense orgs with RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH for encryption, exfiltration, persistence, and USB spread. #APT36 #India #RUSTYSHADE
📢 APT36 déploie RUSTYSHADE, RUSTYMOVE, PSNATCH et BASHNATCH dans l'Opération RapidRust
Cet article détaille l'Opération RapidRust, une campagne attribuée au groupe APT36 (nexus Pakistan), observée en août 2026. La campagne cible des…
🟢 vérification factuelle haute
#APT36 #BASHNATCH #Cyberveille