Iranian State-Backed Nimbus Manticore Expands Toolset With New Backdoor and SSH Tunneler

Cybersecurity researchers at Group-IB have identified additional operational infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps. In an analysis published August 26, 2026, and reported the same day by The Hacker News, Group-IB described the group as among the most active Iranian advanced persistent threat actors of 2026.

Nimbus Manticore — also tracked as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549 — is assessed by Group-IB to be linked to the Tortoiseshell cluster (also known as Imperial Kitten and Unyielding Wasp), itself part of the broader Charming Kitten activity cluster. The group has a documented history of using social-engineering campaigns, including fake recruitment and “Dream Job” lures, to deliver malware to targets in aerospace, defense, IT services, and telecommunications.

New Backdoor and Tunneling Infrastructure Found Across Two Regions

Group-IB researchers Mansour Alhmoud and Mohamed Emam identified a C++ backdoor with characteristics similar to the group’s existing TWOSTROKE implant, along with an SSH-based tunneling utility, deployed across newly discovered infrastructure spanning both Europe and the Middle East. “The discovered Tortoiseshell infrastructure potentially suggests an expanded targeting profile, focusing on Middle Eastern countries, alongside European countries,” the researchers wrote.

The findings follow earlier reporting on the group’s NightLedger backdoor and custom WebSocket tunnelers, which Group-IB said have been used to turn compromised systems into covert network relays capable of executing commands, uploading files, and capturing screenshots while tunneling traffic through victim networks. Group-IB said the continued development of new tools alongside the expanding infrastructure footprint “demonstrates a threat actor that is steadily evolving its toolset and adapting its techniques to maintain access across a growing number of targets.”

Organizations in the aerospace, defense, telecommunications, and critical-infrastructure-adjacent sectors that operate in Europe or the Middle East are advised to review indicators associated with the Tortoiseshell/Nimbus Manticore cluster as part of routine threat-intelligence monitoring.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *