Iran-Linked Tortoiseshell Hackers Expand Espionage With New Backdoor and Reverse SSH Tunnels
Group-IB reported on August 26 that it identified new malware and infrastructure linked to Tortoiseshell, an Iran-linked threat actor also tracked as Mirage Kitten, UNC1549, and Nimbus Manticore, by enriching indicators from prior public reporting
Tortoiseshell's parallel deployment of a reverse SSH tunnel and a redesigned TWOSTROKE-variant backdoor, both masquerading as the same Windows library, gives the group redundant network access that survives detection of any single implant. Country-themed subdomain staging across Britain, Belgium, Saudi Arabia, and the UAE suggests targeting preparation extending beyond Tortoiseshell's traditional Middle East and US defense-aerospace base into Europe. The naming could instead reflect internal staging conventions rather than confirmed geographic targets, since no malware samples yet tie to that infrastructure. Group-IB's enrichment of Kaspersky's earlier indicators, resting on a single primary source with only secondary republication elsewhere, confirms TWOSTROKE remains active and extends known infrastructure across seven additional countries. Defenders in those regions face an early-warning indicator rather than confirmed compromise, and should prioritize hunting unauthorized wtsapi32.dll instances and anomalous outbound SSH over port 443.
4 sources
- Tortoiseshell: New Toolset and Operational Infrastructure Exposed -
Group-IB - Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels -
Cyber Security News - Iran-linked hackers expand infrastructure across Europe and Middle East, report says -
The Record - Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler -
The Hacker News