Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Hacking Group Enhances Malware Arsenal

Iranian Hacking Group Enhances Malware Arsenal

Posted on August 26, 2026 By CWS

Cybersecurity experts have unearthed new malware infrastructure linked to Nimbus Manticore, an Iranian hacking group associated with the Islamic Revolutionary Guard Corps (IRGC). This development underscores the group’s position as one of the most active advanced persistent threat (APT) groups originating from Iran in 2026.

Nimbus Manticore’s Expanding Operations

Group-IB, a prominent cybersecurity firm, has recently published an analysis detailing the activities of Nimbus Manticore, also known by various aliases such as GalaxyGato and Mirage Kitten. The group is believed to have connections with Tortoiseshell, another Iranian cyber threat actor recognized for its long-standing cyber espionage campaigns.

Since at least July 2018, Tortoiseshell has focused on entities within the defense, aerospace, and IT sectors, primarily targeting organizations in the Middle East and the United States. Nimbus Manticore has similarly been involved in campaigns that disguise malware as legitimate job offers to infiltrate these sectors.

Infrastructure and Malware Discoveries

Group-IB’s investigation revealed a broad network of Tortoiseshell infrastructure across Europe and the Middle East. Among their findings was an SSH-based tunneling utility and a C++ backdoor bearing similarities to the TWOSTROKE malware, previously attributed to these threat actors.

The research suggests an expanded scope of targets, now including European countries along with their traditional focus on the Middle East. This expansion is indicative of Nimbus Manticore’s evolving tactics and toolsets, aimed at maintaining persistent access to compromised systems.

Technical Analysis of New Tools

One significant discovery was a reverse SSH tunneling tool disguised as a Windows Terminal Server SDK API, which establishes connections to the threat actor’s infrastructure. Additionally, a new backdoor, resembling the TWOSTROKE malware, was identified. This backdoor is capable of executing various malicious activities, such as system information gathering and file manipulation.

The backdoor operates by mimicking a Windows terminal server SDK DLL and connects to command-and-control servers via HTTPS. Upon receiving instructions, it can download or upload files, execute binaries, and perform other unauthorized operations, showcasing its versatility in cyber intrusions.

According to Group-IB, these findings highlight the continuous development and sophistication of Nimbus Manticore’s cyber tools, posing an ongoing threat to entities in multiple regions.

As cyber threats from state-sponsored groups like Nimbus Manticore continue to evolve, organizations must remain vigilant and adopt robust cybersecurity measures to protect against these sophisticated attacks.

The Hacker News Tags:APT groups, cyber espionage, Cybersecurity, Group-IB, Iranian hacking group, IRGC, Malware, Nimbus Manticore, SSH tunneling, TWOSTROKE

Post navigation

Previous Post: Mirage2FA Bypasses MFA, Compromises Microsoft 365 Accounts
Next Post: Google Chrome 152 Launches with Key Security Fixes

Related Posts

Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security The Hacker News
Revolutionizing Network Detection with AI-Driven NDR Revolutionizing Network Detection with AI-Driven NDR The Hacker News
North Korean Hackers Exploit GitHub in South Korea Cyber Attacks North Korean Hackers Exploit GitHub in South Korea Cyber Attacks The Hacker News
CloudZ Malware Exploits Phone Link for Credential Theft CloudZ Malware Exploits Phone Link for Credential Theft The Hacker News
CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises The Hacker News
Fake OpenAI Repo Delivers Malware on Hugging Face Fake OpenAI Repo Delivers Malware on Hugging Face The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ubiquiti Patches 21 Critical UniFi Vulnerabilities
  • Google Chrome 152 Launches with Key Security Fixes
  • Iranian Hacking Group Enhances Malware Arsenal
  • Mirage2FA Bypasses MFA, Compromises Microsoft 365 Accounts
  • FBI Takes Down Chinese Hacking Platforms Targeting U.S.

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ubiquiti Patches 21 Critical UniFi Vulnerabilities
  • Google Chrome 152 Launches with Key Security Fixes
  • Iranian Hacking Group Enhances Malware Arsenal
  • Mirage2FA Bypasses MFA, Compromises Microsoft 365 Accounts
  • FBI Takes Down Chinese Hacking Platforms Targeting U.S.

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark