Cybersecurity experts have unearthed new malware infrastructure linked to Nimbus Manticore, an Iranian hacking group associated with the Islamic Revolutionary Guard Corps (IRGC). This development underscores the group’s position as one of the most active advanced persistent threat (APT) groups originating from Iran in 2026.
Nimbus Manticore’s Expanding Operations
Group-IB, a prominent cybersecurity firm, has recently published an analysis detailing the activities of Nimbus Manticore, also known by various aliases such as GalaxyGato and Mirage Kitten. The group is believed to have connections with Tortoiseshell, another Iranian cyber threat actor recognized for its long-standing cyber espionage campaigns.
Since at least July 2018, Tortoiseshell has focused on entities within the defense, aerospace, and IT sectors, primarily targeting organizations in the Middle East and the United States. Nimbus Manticore has similarly been involved in campaigns that disguise malware as legitimate job offers to infiltrate these sectors.
Infrastructure and Malware Discoveries
Group-IB’s investigation revealed a broad network of Tortoiseshell infrastructure across Europe and the Middle East. Among their findings was an SSH-based tunneling utility and a C++ backdoor bearing similarities to the TWOSTROKE malware, previously attributed to these threat actors.
The research suggests an expanded scope of targets, now including European countries along with their traditional focus on the Middle East. This expansion is indicative of Nimbus Manticore’s evolving tactics and toolsets, aimed at maintaining persistent access to compromised systems.
Technical Analysis of New Tools
One significant discovery was a reverse SSH tunneling tool disguised as a Windows Terminal Server SDK API, which establishes connections to the threat actor’s infrastructure. Additionally, a new backdoor, resembling the TWOSTROKE malware, was identified. This backdoor is capable of executing various malicious activities, such as system information gathering and file manipulation.
The backdoor operates by mimicking a Windows terminal server SDK DLL and connects to command-and-control servers via HTTPS. Upon receiving instructions, it can download or upload files, execute binaries, and perform other unauthorized operations, showcasing its versatility in cyber intrusions.
According to Group-IB, these findings highlight the continuous development and sophistication of Nimbus Manticore’s cyber tools, posing an ongoing threat to entities in multiple regions.
As cyber threats from state-sponsored groups like Nimbus Manticore continue to evolve, organizations must remain vigilant and adopt robust cybersecurity measures to protect against these sophisticated attacks.
