Security researchers have pieced together fresh evidence of expanded cyber espionage infrastructure operated by Nimbus Manticore, an Iranian state-aligned hacker group tied to the Islamic Revolutionary Guard Corps (IRGC). In its latest report, the Singaporean firm Group-IB links Nimbus Manticore to a growing suite of tools and compromised systems, including malware previously unseen in public disclosures.
Silhouettes of TWOSTROKE and Stealthy Tunneling
The newly reported artifacts include two major components. One is a reverse SSH tunneling utility that is disguised to look like the Windows Terminal Server SDK API. This tool enriches the group’s access by establishing a remote link over SSH to an operator-controlled server (172.86.98[.]113) on port 443. The other component is a backdoor written in C++ that mirrors a known implant called TWOSTROKE. It masquerades as the legitimate Windows Terminal Services DLL “wtsapi32.dll” and uses one of three hard-coded command-and-control servers via HTTPS. Once it connects, it awaits instructions that may range from uploading/downloading files, executing binaries or DLLs, enumerating directories, gathering host telemetry, to deleting specific files. Persistence, system fingerprints, module loading—all inside. All designed to keep a stealthy hold on compromised systems.
Widening Reach and Strategic Targets
Nimbus Manticore (also known under aliases like GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, UNC1549) is tied to the Tortoiseshell cluster (a subset of the Charming Kitten umbrella) and is viewed as among Iran’s most active APT presences in 2026. Tortoiseshell has reportedly been active since at least mid-2018, with a targeting history that includes defense, aerospace, military, and IT service providers in both the Middle East and the United States.
Group-IB’s analysis reveals that the group’s infrastructure now spans Europe and the Middle East, confirming that attacks are not just geographically growing but also shifting in scope. Earlier findings from another firm highlighted tools like NightLedger, BridgeHead, and ArcBridge used in prior Nimbus Manticore campaigns that provide long-term access to compromised hosts. The new additions—this TWOSTROKE-style backdoor and SSH tunneler—underscore an evolution in their tactics toward blending into legitimate Windows flows while maintaining covert connectivity.
The group continues social engineering lures, especially using job-opportunity themes, to gain initial footholds—its so-called Dream Job campaigns. These complement the technical upgrades by exploiting human vulnerabilities, combined with increasingly sophisticated malware, to achieve infiltration and long-term surveillance.
What this means: Nimbus Manticore’s deployment of dual tools—a cloaked backdoor and SSH tunneling mechanism—reveals an APT actor overhauling its playbook. Its ability to expand target regions while using tools that mimic legitimate Windows components signals both ambition and refined operational stealth.
Why it matters: Organizations across Europe, the Middle East, and especially in sectors like defense, aerospace, and critical infrastructure should assume they’re in the crosshairs. Detection will be difficult, because the malware files hide in plain sight (as “wtsapi32.dll”) and communication happens over standard HTTPS and SSH ports. Alertness, endpoint monitoring for unusual DLL loading, and scrutiny of network traffic on port 443 are now essential.
What to watch: Future disclosures may reveal further C2 servers, variants of the backdoor, or new tools with similarly stealthy masquerading. Security teams should track asset-management gaps and ensure regular threat intelligence updates to stay ahead of evolving Iranian APT groups.