Secretus logo
newsapt36transparent-tribezscaler

Operation RapidRust: A Private GitHub Repo Makes a Very Good Covert Channel

Zscaler documents APT36 running command-and-control through private GitHub repositories. The defensive lesson applies to anyone whose egress policy trusts developer platforms.

·6 min read·Secretus Editorial

Your egress policy almost certainly allows github.com. That is the whole idea. Zscaler ThreatLabz has published research on Operation RapidRust, a campaign by the Pakistan-nexus group APT36 — also tracked as Transparent Tribe and Earth Karkaddan — against government and defense organisations in India and Afghanistan. The notable piece of tradecraft is not the malware family. It is that command and control runs through attacker-controlled private GitHub repositories.

That deserves attention outside the targeted region, because the mechanism is not espionage-specific. It is the same shape as a compromised developer account quietly moving your source and your secrets out of the building, through a domain nobody blocks.

What is confirmed

Zscaler ThreatLabz reports observing the activity in August 2026 and attributes it to APT36. The campaign involves four previously undocumented tools: RUSTYSHADE, a Rust-based backdoor; RUSTYMOVE, a Windows USB-propagation component that monitors removable media; PSNATCH, a PowerShell stealer; and BASHNATCH, a Bash equivalent for Linux.

RUSTYSHADE uses attacker-controlled private GitHub repositories for encrypted, bidirectional command and control, reading and writing files through the GitHub REST API. The reported layout is almost mundane: one file carries commands, another carries results, another carries reconnaissance output, another acts as a heartbeat, and image or binary files carry screenshots, webcam captures and exfiltrated content. Supported commands include taking screenshots, capturing a webcam photo, file operations and running commands in the background.

Delivery used typosquatted domains impersonating Indian news outlets, which hosted malicious PowerShell. The actor also used legitimate cloud storage, including Backblaze, to host post-compromise tooling. Zscaler reports that a significant portion of the activity fell between August 20 and September 1, 2026, and that C2 commands were issued only between roughly 4 a.m. and 11 a.m. UTC, on weekdays. PSNATCH is described as targeting files modified within the previous three months — office documents, images, archives, media, executables, scripts and databases — with size limits of 1 GB per file and 5 GB per execution.

What remains unknown

Attribution to a Pakistan-nexus actor is Zscaler's assessment, not something a reader can independently verify. The public research does not establish how many organisations were compromised, which specific entities were affected, or what was ultimately taken. The working-hours pattern is a reasonable inference about the operators' time zone, not a confirmed fact about who they are.

Why this works, and why it matters to you

Three properties make a private repository an unusually good covert channel, and none of them are exotic:

  • The destination is trusted by policy. Domain-based egress filtering permits github.com because blocking it breaks every development workflow. Traffic to the API looks like traffic to the API.
  • The transport is ordinary HTTPS to a real service with a valid certificate, so TLS inspection and reputation scoring have nothing to flag.
  • The repository is private, so the content is not discoverable by anyone scanning public GitHub, and the channel does not depend on infrastructure that can be seized or sinkholed the way a bespoke C2 domain can.

Here is the part directly relevant to secret handling. A private repository is not anonymous: writing to it requires a credential, whether a personal access token, an app installation token or a deploy key. That credential has to live inside the malware. It is a weakness for the attacker—and an opportunity for defenders, because a token used by a piece of malware behaves nothing like a token used by a developer.

It is also the mirror image of a risk you already carry. The same channel that suits an espionage backdoor suits a compromised or disgruntled developer moving credentials, customer data or source code to a repository you do not own. If you cannot detect RUSTYSHADE's traffic pattern, you probably cannot detect that either.

What to do

  1. Know which hosts legitimately talk to the GitHub API. Developer workstations and CI runners, yes. A file server, a print server or a finance workstation, no. Alert on GitHub API usage from systems that have no development role — this is the single highest-value detection here, and it does not require blocking anything.
  2. Stop treating domain allowlisting as egress control. “We allow github.com” is a policy about names, not about data. Where it matters, pair it with volume and pattern monitoring: steady low-rate API writes on a weekday schedule look very different from a developer's bursty activity.
  3. Inventory and scope your own tokens. Replace broad personal access tokens with short-lived, repository-scoped app tokens. Review which tokens can create repositories at organisation level, and alert when new private repositories appear outside the normal process.
  4. Watch the other trusted destinations too. This actor also used legitimate cloud storage for tooling. The same reasoning applies to object-storage providers, paste services and file-transfer platforms that your policy quietly permits.
  5. Do not ignore removable media. One component of this campaign propagates over USB, which is a reminder that air-gapped and segmented networks are reached by the path that crosses the gap.
  6. Verify unexpected news links out of band. The delivery here impersonated well-known news outlets through lookalike domains. For staff in targeted roles, the practical rule is to reach a publication through a bookmark or a search, never through a forwarded link.

Where Secretus fits—and where it does not

Secretus can reduce plaintext exposure when an authorized person must deliver a small, temporary value—a replacement token after you revoke a broad one, a credential handed to a colleague during an investigation—through a channel that does not keep a copy the way mailboxes and tickets do.

It provides nothing that would detect this campaign. It is not an egress control, not a network monitoring tool, and not an endpoint product; it cannot see traffic to a repository, cannot tell a developer's token from malware's, and cannot help once a workstation is already compromised. The detections above are the substance here. The only thing a one-time channel changes is how the replacement credential travels afterwards.

Sources