Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka
Source: The Hacker News · August 26, 2026 at 11:01 PM · AI-assisted report
Single-source
KUALA LUMPUR, MIDDLE EAST, EUROPE, U.S., MALAYSIA, 27 AUGUST 2026 —
Nimbus Manticore Hacking Group Expands Cyber Arsenal with New Malware Tools
Market Impact
KUALA LUMPUR, Aug 26 — Cybersecurity researchers have uncovered additional infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored hacking group tied to the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a report published on Tuesday, identified the group as one of the most active Iranian advanced persistent threat (APT) groups in 2026.
Nimbus Manticore, also known by aliases such as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549, is assessed to be connected to Tortoiseshell (aka Imperial Kitten and Unyielding Wasp), part of the broader Charming Kitten (aka Eclipsed Wasp) cluster. Tortoiseshell has been active since at least July 2018, primarily targeting defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S. Nimbus Manticore has also conducted its own version of the "Dream Job" campaign, using job opportunity-themed social engineering to deliver malware.
Group-IB researchers Mansour Alhmoud and Mohamed Emam noted that the newly discovered Tortoiseshell infrastructure spans Europe and the Middle East, including an SSH-based tunneling utility and a C++ backdoor resembling TWOSTROKE, another tool previously attributed to the threat actor. "The discovered Tortoiseshell infrastructure potentially suggests an expanded targeting profile, focusing on Middle Eastern countries, alongside European countries," they stated.
The findings follow a recent report by Kaspersky, which detailed the group’s use of a new Windows backdoor called NightLedger, along with two custom WebSocket tunnelers, BridgeHead and ArcBridge. These tools were used to maintain persistent access to compromised hosts in attacks targeting entities across the Middle East, Africa, and South Asia.
Among the newly identified malware is a reverse SSH tunneling tool disguised as the Windows Terminal Server SDK API, which establishes an SSH connection to the operator’s infrastructure at 172.86.98[.]113 on port 443. The second malware family is a backdoor that overlaps with TWOSTROKE, a C++ implant enabling system information collection, DLL loading, file manipulation, and persistence. This backdoor mimics the Windows terminal server SDK DLL (wtsapi32.dll) and uses one of three hard-coded command-and-control (C2) servers to establish an HTTPS connection.
Once a response is received from the C2 server, the malware extracts commands and creates a new worker thread to execute them. These commands allow the malware to download/upload files, execute binaries or DLLs, gather host information, list directories, and delete specific files.
"The identification of infrastructure targeting Middle Eastern and European countries alongside continued development of tools such as the TWOSTROKE backdoor and SSH-based tunneling utilities demonstrates a threat actor that is steadily evolving its toolset and adapting its techniques to maintain access across a growing number of targets," Group-IB said.
Malaysia’s Cybersecurity Stake
While the primary targets of Nimbus Manticore remain in the Middle East, Europe, and the U.S., the group’s expanding infrastructure and toolset raise concerns for cybersecurity stakeholders in Malaysia. The country’s increasing digitalization across critical sectors, including finance, telecommunications, and government services, makes it a potential secondary target for state-sponsored cyber espionage.
Local cybersecurity firms and government agencies, such as the National Cyber Security Agency (NACSA) and CyberSecurity Malaysia, are likely to monitor these developments closely. The use of SSH tunneling and backdoors like TWOSTROKE highlights the need for robust endpoint detection, network monitoring, and employee awareness training to mitigate phishing and social engineering risks.
Sector and Company Implications
For Malaysian enterprises, particularly those in defense, aerospace, and IT services, the threat posed by Nimbus Manticore underscores the importance of proactive threat intelligence sharing and collaboration with international cybersecurity firms. Group-IB’s findings suggest that the group’s evolving tactics—such as leveraging legitimate-looking DLLs and SSH connections—require advanced detection mechanisms beyond traditional antivirus solutions.
Companies with operations in the Middle East or Europe should reassess their cybersecurity posture, focusing on lateral movement detection, C2 traffic monitoring, and incident response preparedness. The use of custom tunnelers like BridgeHead and ArcBridge further complicates detection, as these tools can blend into normal network traffic.
Outlook and Recommendations
Cybersecurity experts anticipate that Nimbus Manticore will continue to refine its toolset and expand its targeting scope, particularly in regions with geopolitical significance. The group’s association with the IRGC suggests a long-term strategic focus on intelligence gathering and persistent access.
For Malaysian organizations, the key takeaway is the need for continuous monitoring of emerging threats, regular security audits, and investment in advanced threat detection technologies. Collaboration with regional cybersecurity alliances, such as the ASEAN-Japan Cybersecurity Capacity Building Centre, could also enhance resilience against state-sponsored cyber threats.
Details on the full extent of compromised systems and specific Malaysian targets remain unavailable at this time.