Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
Zscaler, Wednesday, September 16th, 2026
Zscaler ThreatLabz details APT36's Operation RapidRust campaign and its four new Rust-based malware families.
Zscaler ThreatLabz documents Operation RapidRust, an APT36 campaign deploying four newly identified tools: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH.
The research covers initial access, the Rust-based implants' capabilities, and command-and-control infrastructure. It notes the actor's shift toward Rust and cross-platform payloads to complicate detection. Indicators of compromise and detection guidance are published for defenders.