Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RUSTYSHADE is a new 64-bit Windows backdoor written in Rust that abuses attacker-controlled private GitHub repositories for C2 communication.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
ipconfig, ipconfig /all... Identify... network adapter configuration.
APT36 swept 192.168.1.1 through 192.168.1.254 using ping and PowerShell Test-Connection, and used nbtstat and net view to identify network hosts.
APT36 used Test-NetConnection against ports 445 and 135 after identifying live hosts.
APT36 executed hostname, tasklist, echo %COMSPEC%, echo %USERPROFILE%, ipconfig, and ipconfig /all.
HC_LIST List the contents of the current working directory... cd Change the working directory to [path].
APT36 executed net view, net view \\[IP], net share, and net session.
RUSTYSHADE uses the GitHub REST API as its C2 channel... reads and writes specific filenames in the private GitHub repository to synchronize communication.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based Windows backdoor used by APT36. It uses private GitHub repositories and the GitHub REST API for encrypted AES-256-GCM command-and-control, supports command execution, filesystem and drive enumeration, screenshot and webcam capture, and encrypted file collection/exfiltration.
A Rust-based Windows backdoor that uses the GitHub REST API and attacker-controlled private repositories as encrypted AES-256-GCM C2. It supports shell-command execution, directory and drive enumeration, screenshot and webcam capture, and encrypted file exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.