CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

August 26, 2026

Cybersecurity researchers have uncovered new infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB’s analysis describes the actor as among the most active Iranian APT groups in 2026.

Nimbus Manticore, also known as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549, is assessed to be linked to Tortoiseshell (aka Imperial Kitten and Unyielding Wasp), part of the Charming Kitten cluster. Tortoiseshell has been active since at least July 2018, primarily targeting defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S. Nimbus Manticore has also orchestrated its own version of the Dream Job campaign, using job opportunity-themed social engineering to deliver malware.

Group-IB uncovered extensive Tortoiseshell infrastructure spanning Europe and the Middle East, along with an SSH-based tunneling utility and a C++ backdoor sharing similarities with TWOSTROKE, another backdoor attributed to the threat actor. The discovered infrastructure suggests an expanded targeting profile focusing on Middle Eastern and European countries.

The findings build on a recent Kaspersky report detailing the actor’s use of a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, aimed at maintaining persistent access in attacks across the Middle East, Africa, and South Asia.

One newly discovered artifact is a reverse SSH tunneling tool that masquerades as the Windows Terminal Server SDK API, establishing an SSH connection to operator infrastructure at 172.86.98[.]113 on port 443. The second malware family is a backdoor overlapping with TWOSTROKE, a C++ implant enabling system information collection, DLL loading, file manipulation, and persistence. The backdoor mimics the Windows terminal server SDK DLL (wtsapi32.dll) and uses one of three hard-coded C2 servers to establish HTTPS connections and await commands, which allow file upload/download, binary or DLL execution, host information gathering, directory listing, and file deletion.

Group-IB noted that the identification of infrastructure targeting Middle Eastern and European countries, alongside continued tool development, demonstrates a threat actor steadily evolving its toolset and adapting techniques to maintain access across a growing number of targets.

CVEs: CVE-2026-58231

Attack groups: Nimbus Manticore, Tortoiseshell, Charming Kitten

Malware: TWOSTROKE, NightLedger, BridgeHead, ArcBridge

Companies: Group-IB, Kaspersky