<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Rust-Malware on CuraSec</title><link>https://curasec.metacog.co.kr/tags/rust-malware/</link><description>Recent content in Rust-Malware on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 19 Sep 2026 14:22:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/rust-malware/index.xml" rel="self" type="application/rss+xml"/><item><title>Transparent Tribe Uses Rust Backdoor With GitHub C2 Against Gov/Defense</title><link>https://curasec.metacog.co.kr/insights/2026-09-19-transparent-tribe-deploys-new-rust-backdoor-using-private-gi/</link><pubDate>Sat, 19 Sep 2026 14:22:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-19-transparent-tribe-deploys-new-rust-backdoor-using-private-gi/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The use of private GitHub repositories as C2 infrastructure is a technique that can blend into legitimate outbound traffic; no patch action, but worth reviewing whether your egress controls distinguish authorized GitHub API usage from potential C2 beaconing.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> New Rust-compiled implant family (RUSTYSHADE, RUSTYMOVE, PSNATCH, BASHNATCH) using private GitHub repos for C2 is worth building detections for — plan to add rules for anomalous GitHub API egress patterns and Rust-compiled PE artifacts on government/defense-adjacent endpoints.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> APT36 campaign targeting India and Afghanistan government/defense is useful geopolitical context; no immediate board-level action unless your org operates in those sectors or has supply-chain exposure to affected entities.&lt;/li>
&lt;/ul></description></item></channel></rss>