← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Nimbus Manticore Expands Toolset with New Backdoor and SSH Tunneler

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Nimbus Manticore linked to new infrastructure in Europe and Middle East.
  • Discovered an SSH-based tunneling utility.
  • Found a C++ backdoor similar to TWOSTROKE malware.
  • Group is affiliated with Iran's IRGC.

New Malware and Infrastructure Discovered

Cybersecurity researchers have uncovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group. This group is affiliated with the Islamic Revolutionary Guard Corps (IRGC) and is considered one of the most active Iranian APT groups.

The new findings include an SSH-based tunneling utility and a C++ backdoor. The backdoor shares similarities with TWOSTROKE, another piece of malware already attributed to Nimbus Manticore.

Expanded Targeting Profile

Group-IB's analysis suggests that the discovered infrastructure indicates an expanded targeting profile for Nimbus Manticore, focusing on countries in the Middle East and Europe. This builds on previous reports detailing the group's use of other custom tools for persistent access in attacks across the Middle East, Africa, and South Asia.

Technical Details of New Tools

One of the newly identified tools is a reverse SSH tunneling utility that disguises itself as the Windows Terminal Server SDK API. It establishes an SSH connection to the operator's infrastructure at "172.86.98[.]113" on port 443.

The second new malware is a C++ backdoor that mimics the Windows terminal server SDK DLL ("wtsapi32.dll"). This backdoor allows for system information collection, DLL loading, file manipulation, and persistence, communicating with command-and-control servers via HTTPS.

Group Affiliation and History

Nimbus Manticore, also known by aliases such as GalaxyGato and Smoke Sandstorm, is linked to the Tortoiseshell group, which has been active since at least July 2018. Tortoiseshell primarily targets defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S. Nimbus Manticore has also conducted social engineering campaigns using job opportunity themes to deliver malware.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~10 min · 8 stories · Aug 26

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers identified new infrastructure and malware used by Nimbus Manticore, an Iranian state-sponsored hacking group. The discoveries include an SSH-based tunneling utility and a C++ backdoor similar to their existing TWOSTROKE malware, indicating an expanded targeting profile.