CuraSec

tag: Github-C2 · 1 items

2026-09-19 · The Hacker News · source ↗ #apt36#rust-malware#github-c2
  • Engineer — Learn: The use of private GitHub repositories as C2 infrastructure is a technique that can blend into legitimate outbound traffic; no patch action, but worth reviewing whether your egress controls distinguish authorized GitHub API usage from potential C2 beaconing.
  • SOC/IR — Plan: New Rust-compiled implant family (RUSTYSHADE, RUSTYMOVE, PSNATCH, BASHNATCH) using private GitHub repos for C2 is worth building detections for — plan to add rules for anomalous GitHub API egress patterns and Rust-compiled PE artifacts on government/defense-adjacent endpoints.
  • Leader — Learn: APT36 campaign targeting India and Afghanistan government/defense is useful geopolitical context; no immediate board-level action unless your org operates in those sectors or has supply-chain exposure to affected entities.