Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iran-Linked Cyber Group Intensifies Attacks with New Methods

Iran-Linked Cyber Group Intensifies Attacks with New Methods

Posted on August 26, 2026 By CWS

Iran-linked cybercriminals have intensified their espionage activities by deploying a novel Windows backdoor and utilizing reverse SSH tunneling. These operations are attributed to the group known as Tortoiseshell, also identified by aliases such as Mirage Kitten, UNC1549, and Nimbus Manticore.

Advanced Techniques for Sustained Access

The hackers have developed mechanisms to maintain prolonged access to compromised networks. Their tunneling tool allows traffic redirection from a server controlled by the attackers to the victim’s network. Simultaneously, the backdoor facilitates command execution, file transfers, and data collection from infected systems.

Group-IB, a cybersecurity firm, has discovered additional malware and infrastructure through enriched threat indicators and rigorous threat hunting. This indicates that Tortoiseshell is extending its reach across targets in the Middle East and Europe.

Historical Context and Entry Methods

Active since at least 2018, Tortoiseshell has primarily focused on sectors like defense, aerospace, IT services, and military organizations. Their infiltration techniques include supply-chain compromises, fake recruitment sites, and compromised websites, emphasizing the necessity for user vigilance and robust security measures.

A recent report by Group-IB, shared with Cyber Security News, highlights the broader implications of these activities for organizations managing strategic or government-related data. The report underscores the persistent threats faced by high-value sectors in the region.

Technical Analysis of the Malware Components

One notable component discovered is a malicious Windows library masquerading as the legitimate wtsapi32.dll, which is linked to Terminal Server functions. This library covertly initiates a reverse SSH connection over port 443, establishing a link to the operators’ server.

Another identified sample is a C++ implant akin to the TWOSTROKE backdoor. It employs DLL search-order hijacking to deceive trusted programs into loading the malicious library. This backdoor can receive commands to upload or steal files, execute programs, and perform other malicious actions.

Infrastructure and Global Reach

Further investigation by Group-IB revealed additional infrastructure linked to the operation, with domains and subdomains suggesting affiliations with countries like the United Arab Emirates, Saudi Arabia, the UK, Belgium, Canada, Australia, and Japan. Despite the absence of matching samples for each node, the geographic pattern suggests deliberate planning.

The findings emphasize the importance of monitoring for unusual DLL side-loading and outbound SSH traffic, particularly on port 443. Network teams should remain vigilant for unexpected SSH activity from Windows processes, as it may indicate an ongoing intrusion.

Overall, organizations in the affected sectors must prioritize proactive threat hunting and share intelligence with trusted partners to mitigate the risks posed by these persistent cyber threats.

Cyber Security News Tags:Backdoor, cyber attacks, Cybersecurity, Espionage, Group-IB, Iran-linked hackers, Malware, Middle East, SSH tunneling, Tortoiseshell

Post navigation

Previous Post: AI Accelerates Malware Creation, But Not Its Effectiveness
Next Post: New SLEEPWALKER Backdoor Uses Unique Trigger Mechanism

Related Posts

PoC Exploit Released for Linux-PAM Vulnerability Allowing Root Privilege Escalation PoC Exploit Released for Linux-PAM Vulnerability Allowing Root Privilege Escalation Cyber Security News
Hackers Leverage X’s Grok AI To Amplify Malicious Links Via Promoted Posts Hackers Leverage X’s Grok AI To Amplify Malicious Links Via Promoted Posts Cyber Security News
Top Malware Sandbox Tools Enhancing Security in 2026 Top Malware Sandbox Tools Enhancing Security in 2026 Cyber Security News
20 Best Kubernetes Monitoring Tools in 2025 20 Best Kubernetes Monitoring Tools in 2025 Cyber Security News
Cisco ISE Flaws Enable Remote Code Execution Risk Cisco ISE Flaws Enable Remote Code Execution Risk Cyber Security News
Turla’s Advanced Espionage Operations in Ukraine Uncovered Turla’s Advanced Espionage Operations in Ukraine Uncovered Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bug in WordPress Plugin Risks 400,000 Sites
  • New SLEEPWALKER Backdoor Uses Unique Trigger Mechanism
  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bug in WordPress Plugin Risks 400,000 Sites
  • New SLEEPWALKER Backdoor Uses Unique Trigger Mechanism
  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark