← Back to blog

Iranian APT Group Nimbus Manticore Deploys New Backdoor and Tunneling Tools

Nimbus Manticore, an Iranian state-sponsored hacking group, has expanded its arsenal with new backdoor and SSH tunneling capabilities. Security researchers warn of increased espionage activity targeting global organizations.

TL;DR

  • Nimbus Manticore linked to IRGC adds TWOSTROKE-like backdoor and SSH tunneler
  • Group-IB identifies new malware and infrastructure used in 2026 campaigns
  • Targets include government, defense, and critical infrastructure sectors
  • Tools enable persistent access and covert data exfiltration
  • Security teams should monitor for unusual SSH traffic and unknown backdoors

Cybersecurity firm Group-IB has uncovered new tools and infrastructure linked to Nimbus Manticore, an Iranian advanced persistent threat (APT) group with ties to the Islamic Revolutionary Guard Corps (IRGC). The discoveries highlight the group's evolving tactics in global cyberespionage operations throughout 2026.

The newly identified malware includes a backdoor resembling TWOSTROKE and an SSH tunneling utility that allows the attackers to maintain stealthy, long-term access to compromised networks. These tools enhance the group's ability to conduct surveillance and extract sensitive data from targeted organizations.

New Malware Arsenal

  • Researchers discovered a TWOSTROKE-like backdoor used for initial access and command execution
  • An SSH tunneling tool enables covert communication channels and bypasses network defenses
  • Both tools are designed to evade detection by standard security monitoring systems
  • The malware is typically deployed through spear-phishing or compromised web applications

Operational Impact and Defense

  • Nimbus Manticore remains highly active in targeting government and defense sectors globally
  • Organizations should audit SSH configurations and monitor for anomalous tunneling activity
  • Endpoint detection and response (EDR) solutions should be updated with new IOCs
  • Web application firewalls should block suspicious payloads and unauthorized outbound connections

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.