IntroductionIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan.
Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
About this summary. This is a short, independently written summary of an article first published by Zscaler ThreatLabz. Cyber Security News did not report or verify the underlying story. Read the original: https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and

Source attribution: headline and facts are from Zscaler ThreatLabz (zscaler.com). Summary method: excerpt of the source description. See our source attribution policy.




