Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
From the source: Zscaler ThreatLabzIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense…
Read the full story on Zscaler ThreatLabzHave you worked with this?
The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.
More from Zscaler
Recent updates from Zscaler, so you can tell whether this is a one-off or part of a pattern.
Threat Actors Use Google Ads To Target Ledger Users
In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…
Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation
Vidar is an information stealer that was first observed in 2018. Across its iterations, Vidar has continued to improve its string obfuscation to make detection and analysis more difficult by changing deobfuscation algorithms, constants, and primitives. From May through early September 2026, Zscaler ThreatLabz tracked Vidar’s string obfuscation as it evolved from basic XOR to ChaCha20,…
SloppyRAT: A New Tool For Ransomware Attacks
In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including a large number of built-in PowerShell-like commands, encrypted code blocks, EtherHiding…
More in Security
What other companies in Security are doing. The category page shows who’s active, side by side.
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Two Things Every Cyber Asset Attack Surface Management (CAASM) Tool Needs to Get Right
Cyber Asset Attack Surface Management (CAASM) solved a significant problem. Security teams can now say with confidence what they own. But, two things separate a CAASM tool that stops there from one that actually moves the needle on risk. The first is what the inventory itself carries. The second is what it connects to. 1. An inventory needs to do more than list what exists A list of assets is…
Agents can now set up your website’s security with Turnstile Spin
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.
Darktrace / SECURE AI: Behavioral Security for the AI enterprise
Discover how Darktrace / SECURE AI applies behavioral security to AI usage, prompts, agents, and development to help organizations adopt AI securely.


