← Blog · · df00tech

Nimbus Manticore Adds a TWOSTROKE-Style Backdoor and SSH Tunneler to Its Toolkit

security-news campaign

What happened

Group-IB has published new research on Nimbus Manticore, an Iranian state-sponsored espionage actor tied to the IRGC, describing it as one of the most active Iranian APT groups observed in 2026. The report identifies previously undocumented malware and additional infrastructure linked to the group, including a backdoor resembling the known TWOSTROKE family and a dedicated SSH tunneling tool. Details on victimology, initial access, and full technical indicators were not included in the summary available at publication time, so specifics should be treated as pending further disclosure.

Why it matters for defenders

Nimbus Manticore is attributed to a state-sponsored actor conducting cyber espionage, which typically means long-dwell, targeted intrusions against government, diplomatic, defense, and related sectors rather than opportunistic mass exploitation. The addition of a new backdoor variant and an SSH tunneler suggests the group is investing in both persistent access and covert internal/external connectivity — tunneling tools in particular are often used to bridge segmented networks or proxy command-and-control traffic through otherwise-trusted channels, which can complicate detection and containment.

What defenders should watch for

  • Unusual or unauthorized SSH client/tunneling activity, especially outbound connections from hosts that don't normally initiate SSH, or SSH traffic on non-standard ports
  • New or unexpected persistence mechanisms and backdoor-style implants on systems associated with high-value or targeted user populations (government, policy, defense-adjacent organizations)
  • Anomalous process trees spawning network tooling (SSH clients, port-forwarding utilities) from non-administrative accounts or unexpected parent processes
  • Threat-intel feeds and IOC releases from Group-IB and other vendors for concrete hashes, C2 infrastructure, and file paths as they become available, so they can be operationalized into detections
  • General hardening against IRGC-linked TTPs: monitoring for spear-phishing delivery, credential harvesting, and lateral movement consistent with past Iranian APT campaigns

Developing story

This is based on a single vendor report and reflects early, evolving intelligence — technical indicators, full TTP mapping, and victim scope may be refined as more analysis is published. No CVE or specific exploited vulnerability has been associated with this activity in the reporting reviewed. For full details, see the original coverage at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.