Nimbus Manticore Deploys TWOSTROKE Backdoor and SSH Tunneler in Europe-Middle East Spying Campaign
Cybersecurity researchers at Group-IB have uncovered fresh infrastructure and previously undocumented malware tied to Nimbus Manticore, an Iranian state-sponsored APT group operating under the Islamic Revolutionary Guard Corps (IRGC). Tracked under multiple aliases including GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549, the cluster is assessed as a subordinate element of Tortoiseshell (Imperial Kitten, Unyielding Wasp), which itself nests within the broader Charming Kitten (Eclipsed Wasp) ecosystem active since at least July 2018. Group-IB analysts Mansour Alhmoud and Mohamed Emam described Nimbus Manticore as one of the most active Iranian APT groups in 2026, noting its continued use of the Dream Job social engineering playbook to lure defense, aerospace, IT services, and military personnel in the U.S. and Middle East.
The newly catalogued arsenal includes a reverse SSH tunneling utility and a C++ backdoor that overlaps significantly with TWOSTROKE, a custom implant already attributed to the actor. The SSH tunneler impersonates the Windows Terminal Server SDK API while establishing outbound SSH sessions to attacker-controlled infrastructure hosted at 172.86.98[.]113 over port 443, granting operators a persistent foothold inside compromised environments. The companion backdoor mimics the legitimate wtsapi32.dll, beacons to one of three hard-coded command-and-control servers over HTTPS, and extracts operator instructions from server responses before spawning a dedicated worker thread to execute them. Security teams investigating exposure can review suspicious outbound connections using a port scanner to identify anomalous activity on TCP/443, and run a WHOIS lookup on any unfamiliar C2 IP addresses such as 172.86.98[.]113 to trace hosting attribution.
Capabilities baked into the TWOSTROKE-derived implant include system information collection, DLL side-loading, file manipulation, persistence establishment, directory enumeration, file deletion, and the ability to download, upload, or execute arbitrary binaries and DLLs. The findings extend a recent Kaspersky report detailing the NightLedger Windows backdoor alongside the BridgeHead and ArcBridge WebSocket tunnelers, which were used to maintain stealthy access across entities in the Middle East, Africa, and South Asia. Together, the two analyses paint a picture of a tradecraft-rich adversary investing heavily in multi-stage persistence and traffic-mimicking loaders designed to blend with native Windows telemetry.
Group-IB warns that the breadth of newly discovered Tortoiseshell infrastructure spanning Europe and the Middle East signals an expanded targeting profile, with the group now pursuing organizations beyond its traditional U.S. and Gulf-state focus. Defenders in affected sectors are urged to audit egress traffic for unauthorized SSH sessions, hunt for unsigned binaries masquerading as wtsapi32.dll, and review identity exposures with an email breach checker to determine whether personnel credentials surfaced in prior Dream Job lures remain exploitable. The convergence of custom tunneling frameworks with modular backdoor variants underscores the group's operational maturity and its intent to sustain long-term espionage access against high-value geopolitical targets.