Adversary Intelligence — 2026-08-27

Iran-Linked Tortoiseshell Hackers Expand Espionage With New Backdoor and Reverse SSH Tunnels

BLUFTortoiseshell's redundant implant design and country-themed staging infrastructure signal pre-positioning for espionage campaigns across Europe, broadening a threat previously confined to the Middle East and US defense sectors.

Group-IB reported on August 26 that it identified new malware and infrastructure linked to Tortoiseshell, an Iran-linked threat actor also tracked as Mirage Kitten, UNC1549, and Nimbus Manticore, by enriching indicators from prior public reporting 1. The firm found a reverse SSH tunneling tool and a C++ backdoor resembling the previously documented TWOSTROKE family, which Google Cloud Threat Intelligence Group first reported in late 2025, both disguised as the legitimate Windows file wtsapi32.dll 12. The tunneling tool connects outbound to an operator server at 172.86.98.113 over port 443, then routes traffic back into the victim network, while the backdoor uses hardcoded HTTPS command-and-control domains including neexportfolio.com 1. Pivoting from a known control domain, Group-IB mapped additional servers with country-themed subdomain names tied to the UAE, Saudi Arabia, the UK, Belgium, Canada, Australia, and Japan, though it said no matching malware samples confirmed the purpose of that infrastructure 13. The Record reported that Group-IB separately confirmed Belgium-, Saudi-, and UAE-based infrastructure to it directly 3.

Analysis
Tortoiseshell's parallel deployment of a reverse SSH tunnel and a redesigned TWOSTROKE-variant backdoor, both masquerading as the same Windows library, gives the group redundant network access that survives detection of any single implant. Country-themed subdomain staging across Britain, Belgium, Saudi Arabia, and the UAE suggests targeting preparation extending beyond Tortoiseshell's traditional Middle East and US defense-aerospace base into Europe. The naming could instead reflect internal staging conventions rather than confirmed geographic targets, since no malware samples yet tie to that infrastructure. Group-IB's enrichment of Kaspersky's earlier indicators, resting on a single primary source with only secondary republication elsewhere, confirms TWOSTROKE remains active and extends known infrastructure across seven additional countries. Defenders in those regions face an early-warning indicator rather than confirmed compromise, and should prioritize hunting unauthorized wtsapi32.dll instances and anomalous outbound SSH over port 443.
4 sources
  1. Tortoiseshell: New Toolset and Operational Infrastructure Exposed - Group-IB
  2. Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels - Cyber Security News
  3. Iran-linked hackers expand infrastructure across Europe and Middle East, report says - The Record
  4. Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE