Transparent Tribe Deploys New Rust-Based Backdoor in Targeted Campaigns Against Government and Defense Entities
Zscaler ThreatLabz reports group uses private GitHub repositories for C2 infrastructure, leveraging previously undocumented tools RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH.

Key Takeaways
- Transparent Tribe (APT36/Earth Karkaddan) has launched new campaigns targeting government and defense entities in India and Afghanistan.
- The group is using previously undocumented Rust-based tools: RUSTYSHADE (backdoor), RUSTYMOVE (lateral movement/exfiltration), PSNATCH (credential harvesting), and BASHNATCH (persistence).
Related Security News

Citrix NetScaler Zero-Days Exploited in the Wild; Agencies Urge Immediate Restriction
Cybersecurity agencies, security researchers, and IT providers are warning that two zero-day vulnerabilities in Citrix NetScaler products are being actively exploited in the wild. Exploitation was reported in late September 2026, with private and public advisories issued ahead of patches expected to be released next week. Organizations using unpatched NetScaler appliances face risks of unauthorized access, data exfiltration, and service disruption. Until patches are applied, administrators are advised to shut down or restrict NetScaler appliances.

AI Agents Introduce New Lateral Movement Vectors in Cybersecurity Landscape
A recent analysis published on The Hacker News examines how AI agents differ from deterministic applications in cybersecurity operations, raising concerns about autonomous path discovery and task completion capabilities. The report highlights that AI agents can relentlessly pursue task completion, potentially discovering and exploiting unexpected access paths that traditional least-privilege models may not address.



