The latest cyber espionage campaign attributed to Transparent Tribe (APT36), known as Operation RapidRust, highlights an increasingly important challenge for enterprise cybersecurity: attackers are exploiting legitimate cloud infrastructure to steal sensitive information while attempting to blend their malicious communications with normal business traffic. The campaign, reported by Zscaler ThreatLabz, targets government and defence organisations in India and Afghanistan and introduces malware capable of remote access, information collection, data theft and removable-media propagation. Particularly concerning is the use of attacker-controlled private GitHub repositories for command-and-control communications and the exfiltration of stolen information. This approach challenges conventional security models that primarily rely on identifying known malicious IP addresses, suspicious domains or previously identified malware signatures.
The campaign employs a collection of malicious tools designed to operate across Windows and Linux environments. RUSTYSHADE, a Rust-based backdoor, uses the GitHub REST API to communicate with attacker-controlled repositories, enabling remote command execution and information collection. PSNATCH, a PowerShell-based information stealer, searches Windows systems for files of interest and uploads collected information to private repositories, while BASHNATCH provides similar data-stealing functionality for Linux systems. The toolkit also includes RUSTYMOVE, which copies malicious files onto removable USB drives. These capabilities demonstrate how attackers can combine endpoint compromise, trusted cloud communication and data collection into a coordinated espionage operation. The critical concern for organisations is that confidential information may leave the network through HTTPS connections to services that are otherwise considered legitimate.
Why Traditional Network Security May Miss the Actual Threat
Traditional firewall policies frequently classify traffic according to destination IP addresses, domain reputation, application identification and predefined access rules. While these controls remain important, they may not be sufficient when an attacker uses a legitimate platform such as GitHub for malicious operations. An organisation might permit access to GitHub because its development teams use the service for source-code management, software updates and collaboration. Once that access is permitted, malware communicating with attacker-controlled repositories may attempt to exploit the same trusted communication path. From the network perspective, both legitimate development activity and malicious data exfiltration can involve HTTPS connections to GitHub infrastructure. Simply identifying the destination as GitHub does not establish whether the activity is authorised, whether the uploaded information is appropriate or whether the application initiating the connection is legitimate.
This is where conventional destination-based security controls encounter an important limitation. Blocking GitHub entirely may disrupt legitimate operations, while allowing unrestricted access could create opportunities for unauthorised data transfers. Even advanced techniques such as JA3 and JA4 TLS fingerprinting provide only supporting evidence because a TLS fingerprint identifies characteristics of a client implementation rather than the intent of a particular connection. Different legitimate and malicious applications may share similar fingerprints, and attackers can modify networking implementations to change their fingerprints. Similarly, identifying suspicious traffic volumes alone may not expose an attacker who transfers relatively small quantities of sensitive documents over an extended period. Effective protection requires understanding the context surrounding the communication, including the source system, authorised application, user identity, sensitivity of the information and permitted destination.
Contextual Data Leak Prevention: Understanding What Is Leaving the Network and Why
Operation RapidRust illustrates the need for Contextual Data Leak Prevention (DLP), an approach that evaluates data movement in relation to organisational policies and the circumstances surrounding the transfer. Instead of treating every connection to a trusted cloud service as safe or automatically treating every upload as malicious, contextual DLP can apply policies based on the user, device, application, destination and classification of the information being transferred. For example, an authorised developer uploading approved source code to an organisation-controlled GitHub repository represents a different security scenario from an employee workstation unexpectedly uploading confidential government documents to an unapproved private repository. Although both activities may use the same cloud service and HTTPS protocol, the security implications are fundamentally different.
The distinction becomes particularly important when attackers use legitimate cloud APIs rather than dedicated malicious infrastructure. An effective contextual DLP architecture should be capable of identifying sensitive information, enforcing destination-specific policies and restricting unauthorised transfers according to organisational requirements. Where supported and appropriately deployed, HTTPS inspection and application-aware controls can provide visibility into relevant API requests, repository destinations and uploaded content. Organisations must also account for technical limitations: encrypted traffic that cannot be decrypted may reveal only metadata, and information encrypted by malware before transmission may not be available for content inspection. Consequently, contextual DLP should operate alongside endpoint monitoring, process visibility and threat intelligence rather than being treated as a standalone solution capable of identifying every form of exfiltration.
GajShield's Contextual DLP Approach to Protecting Sensitive Information
The threat demonstrated by Operation RapidRust directly illustrates the security problem that GajShield's Contextual Data Leak Prevention approach is designed to address: protecting organisational information based on the circumstances of its movement rather than relying exclusively on destination-based access decisions. A policy-driven security architecture can distinguish authorised business communications from potentially unauthorised data transfers by combining relevant context such as source networks, users, applications, destinations and data sensitivity, subject to the visibility and enforcement capabilities available in the deployment. This enables organisations to implement more granular security policies while continuing to permit legitimate access to essential cloud services. For environments handling sensitive government documents, defence information, intellectual property and confidential business records, the objective is to control how information is permitted to leave the network, even when the destination itself is a widely trusted platform.
In a GitHub-based exfiltration scenario, contextual controls become particularly valuable when an organisation needs to permit legitimate developer activity while restricting other systems from transferring sensitive information to external repositories. Security policies could, for example, allow designated development systems to access approved GitHub destinations while restricting uploads from sensitive network segments or other unauthorised systems. Where appropriate application-level visibility is available, policies can be refined further to distinguish authorised and unauthorised repository operations. Correlation with intrusion prevention signatures, threat intelligence and endpoint alerts can strengthen investigations by connecting suspicious outbound activity with evidence of malware execution or system compromise. These measures should be validated against the specific GajShield deployment and its supported inspection capabilities; the discovery of Operation RapidRust does not, by itself, establish that a particular malware sample or GitHub API operation is already detected or blocked.
Moving from Destination-Based Trust to Context-Aware Data Protection
The larger lesson from Operation RapidRust is that attackers are increasingly exploiting the gap between trusted infrastructure and trusted behaviour. A legitimate cloud platform does not automatically make every communication passing through it legitimate, just as an encrypted connection does not guarantee that the information being transferred is authorised. Organisations must therefore move beyond security decisions based solely on IP addresses, domains and individual malware signatures. They need visibility into how information moves across the network, which systems initiate transfers, what information is being shared and whether those actions comply with established security policies. This requires a coordinated approach that combines contextual DLP, application-aware network security, endpoint detection, threat intelligence and carefully defined access policies.
For government, defence and enterprise environments, the priority should be to prevent unauthorised disclosure of sensitive information without unnecessarily disrupting legitimate cloud adoption. Operation RapidRust demonstrates why the protection of data must remain a central objective even when attackers change their malware, rotate infrastructure or exploit trusted services. By evaluating network activity in its proper context and applying security policies to the movement of information, organisations can strengthen their ability to identify and restrict suspicious data transfers that conventional destination-based controls may overlook. **In an environment where attackers can hide behind trusted cloud infrastructure, effective cybersecurity requires more than knowing where traffic is going. It requires understanding what information is leaving, who is sending it, and whether that transfer should be permitted.**

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation
Source: Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 via The Hacker News — published 18 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.