APT36 RUSTYSHADE Backdoor Execution (DriverInstaller.exe)
Detects the execution of the RUSTYSHADE Rust-based backdoor, observed during Operation RapidRust, associated with the threat group APT36 (Transparent Tribe). The rule monitors for the specific 'DriverInstaller.exe' filename, known malicious file hashes, and suspicious command-line patterns involving PowerShell-based downloads of 'DriverInstaller.zip' from Backblaze cloud storage.
Sigma

