VYPR
researchPublished Sep 18, 2026· 1 source

Transparent Tribe Targets India, Afghanistan with New Rust Backdoors and GitHub C2

The Pakistan-aligned APT group Transparent Tribe has launched new cyberattacks against Indian and Afghan government and defense entities, employing novel Rust-based malware and leveraging private GitHub repositories for command and control.

Transparent Tribe, a persistent threat actor also known as APT36 and Earth Karkaddan, has been identified by Zscaler ThreatLabz as the perpetrator of a new wave of cyberattacks targeting critical government and defense infrastructure in India and Afghanistan. This campaign marks a significant evolution in the group's tactics, techniques, and procedures (TTPs), introducing a suite of previously undocumented malware tools.

The newly discovered malware includes RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. These tools are designed to provide Transparent Tribe with advanced capabilities for espionage, data exfiltration, and maintaining persistent access within compromised networks. The use of Rust, a modern systems programming language known for its performance and memory safety, suggests a deliberate effort by the threat group to develop more sophisticated and potentially harder-to-detect malicious software.

A particularly noteworthy aspect of this campaign is the group's innovative use of private GitHub repositories for command and control (C2) infrastructure. By utilizing GitHub, a widely used platform for software development, Transparent Tribe can blend its malicious C2 traffic with legitimate developer activity, making it more challenging for security defenses to identify and block. This approach also offers a degree of resilience and ease of management for the threat actor's infrastructure.

The primary targets of this campaign are entities within the Indian and Afghan government and defense sectors. This focus aligns with Transparent Tribe's historical objectives, which often involve gathering intelligence on geopolitical adversaries and potentially disrupting their operations. The choice of targets underscores the group's continued interest in South Asian regional security dynamics.

While specific details on the initial infection vector are still emerging, the deployment of these new tools suggests a multi-stage attack process. The malware suite likely includes components for initial access, privilege escalation, lateral movement, and data exfiltration, all orchestrated through the GitHub-based C2 channels. The sophistication of the tools and infrastructure indicates a well-resourced and determined threat actor.

Security researchers are actively analyzing the new malware samples to understand their full capabilities and identify potential indicators of compromise (IoCs). Organizations in the targeted regions, particularly those within government and defense, are advised to enhance their network monitoring, endpoint detection, and threat intelligence capabilities. Vigilance against phishing attempts and robust security hygiene remain critical defenses against such advanced persistent threats.

The ongoing activity by Transparent Tribe highlights the persistent threat posed by nation-state-backed actors and their continuous efforts to refine their toolsets and operational methods. The adoption of newer programming languages like Rust and the creative use of legitimate platforms for C2 infrastructure demonstrate an adaptive adversary that security professionals must continuously monitor and counter.

Synthesized by Vypr AI