Iranian APT Group Nimbus Manticore Deploys New Backdoor and Tunneling Tools
Nimbus Manticore, an Iranian state-sponsored hacking group, has expanded its arsenal with new backdoor and SSH tunneling capabilities. Security researchers warn of increased espionage activity targeting global organizations.
TL;DR
- Nimbus Manticore linked to IRGC adds TWOSTROKE-like backdoor and SSH tunneler
- Group-IB identifies new malware and infrastructure used in 2026 campaigns
- Targets include government, defense, and critical infrastructure sectors
- Tools enable persistent access and covert data exfiltration
- Security teams should monitor for unusual SSH traffic and unknown backdoors
Cybersecurity firm Group-IB has uncovered new tools and infrastructure linked to Nimbus Manticore, an Iranian advanced persistent threat (APT) group with ties to the Islamic Revolutionary Guard Corps (IRGC). The discoveries highlight the group's evolving tactics in global cyberespionage operations throughout 2026.
The newly identified malware includes a backdoor resembling TWOSTROKE and an SSH tunneling utility that allows the attackers to maintain stealthy, long-term access to compromised networks. These tools enhance the group's ability to conduct surveillance and extract sensitive data from targeted organizations.
New Malware Arsenal
- Researchers discovered a TWOSTROKE-like backdoor used for initial access and command execution
- An SSH tunneling tool enables covert communication channels and bypasses network defenses
- Both tools are designed to evade detection by standard security monitoring systems
- The malware is typically deployed through spear-phishing or compromised web applications
Operational Impact and Defense
- Nimbus Manticore remains highly active in targeting government and defense sectors globally
- Organizations should audit SSH configurations and monitor for anomalous tunneling activity
- Endpoint detection and response (EDR) solutions should be updated with new IOCs
- Web application firewalls should block suspicious payloads and unauthorized outbound connections
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.