Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
AI-summarised brief · reviewed before publication
Cybersecurity firm Group‑IB has uncovered new infrastructure and previously unknown malware linked to Iran’s state‑sponsored APT group Nimbus Manticore, also known as GalaxyGato and several other aliases. The researchers say the group, tied to the Islamic Revolutionary Guard Corps and related to the Tortoiseshell/Charming Kitten cluster, is among the most active Iranian actors in 2026. Findings include a reverse‑SSH tunneling utility that pretends to be the Windows Terminal Server SDK API and connects to a hard‑coded server (172.86.98[.]113:443), and a C++ backdoor resembling the TWOSTROKE implant. Both tools enable persistent access, system data collection, file manipulation and command execution. The infrastructure spans Europe and the Middle East, suggesting an expanded targeting profile beyond the group’s historic focus on defense and aerospace sectors.
💡 Why It Matters
- · By integrating a disguised SSH tunnel and a TWOSTROKE‑like backdoor, Nimbus Manticore can stealthily maintain footholds across a broader geographic swath, giving Iran a more resilient channel for espionage against strategic industries.