Iran-linked cybercriminals have intensified their espionage activities by deploying a novel Windows backdoor and utilizing reverse SSH tunneling. These operations are attributed to the group known as Tortoiseshell, also identified by aliases such as Mirage Kitten, UNC1549, and Nimbus Manticore.
Advanced Techniques for Sustained Access
The hackers have developed mechanisms to maintain prolonged access to compromised networks. Their tunneling tool allows traffic redirection from a server controlled by the attackers to the victim’s network. Simultaneously, the backdoor facilitates command execution, file transfers, and data collection from infected systems.
Group-IB, a cybersecurity firm, has discovered additional malware and infrastructure through enriched threat indicators and rigorous threat hunting. This indicates that Tortoiseshell is extending its reach across targets in the Middle East and Europe.
Historical Context and Entry Methods
Active since at least 2018, Tortoiseshell has primarily focused on sectors like defense, aerospace, IT services, and military organizations. Their infiltration techniques include supply-chain compromises, fake recruitment sites, and compromised websites, emphasizing the necessity for user vigilance and robust security measures.
A recent report by Group-IB, shared with Cyber Security News, highlights the broader implications of these activities for organizations managing strategic or government-related data. The report underscores the persistent threats faced by high-value sectors in the region.
Technical Analysis of the Malware Components
One notable component discovered is a malicious Windows library masquerading as the legitimate wtsapi32.dll, which is linked to Terminal Server functions. This library covertly initiates a reverse SSH connection over port 443, establishing a link to the operators’ server.
Another identified sample is a C++ implant akin to the TWOSTROKE backdoor. It employs DLL search-order hijacking to deceive trusted programs into loading the malicious library. This backdoor can receive commands to upload or steal files, execute programs, and perform other malicious actions.
Infrastructure and Global Reach
Further investigation by Group-IB revealed additional infrastructure linked to the operation, with domains and subdomains suggesting affiliations with countries like the United Arab Emirates, Saudi Arabia, the UK, Belgium, Canada, Australia, and Japan. Despite the absence of matching samples for each node, the geographic pattern suggests deliberate planning.
The findings emphasize the importance of monitoring for unusual DLL side-loading and outbound SSH traffic, particularly on port 443. Network teams should remain vigilant for unexpected SSH activity from Windows processes, as it may indicate an ongoing intrusion.
Overall, organizations in the affected sectors must prioritize proactive threat hunting and share intelligence with trusted partners to mitigate the risks posed by these persistent cyber threats.
