Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Group-IB uncovered new infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored APT group affiliated with the IRGC Researchers discovered an SSH-based reverse tunneling utility masquerading as the Windows Terminal Server SDK API and a C++ backdoor sharing similarities with the previously known TWOSTROKE implant The backdoor mimics wtsapi32.dll, connects to one of three hard-coded C2 servers over HTTPS, and supports file manipulation, DLL loading,
Analysis
TL;DR
- Group-IB uncovered new infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored APT group affiliated with the IRGC
- Researchers discovered an SSH-based reverse tunneling utility masquerading as the Windows Terminal Server SDK API and a C++ backdoor sharing similarities with the previously known TWOSTROKE implant
- The backdoor mimics wtsapi32.dll, connects to one of three hard-coded C2 servers over HTTPS, and supports file manipulation, DLL loading, command execution, and persistence mechanisms
- Tortoiseshell infrastructure was found spanning Europe and the Middle East, suggesting an expanded targeting profile beyond previous operations
- These findings complement Kaspersky's recent report on NightLedger backdoor and custom WebSocket tunnelers (BridgeHead and ArcBridge), indicating a steadily evolving toolset
Why It Matters
This discovery highlights the rapid evolution of Iranian state-sponsored threat actors and their increasing sophistication in tool development and infrastructure expansion. For AI and cybersecurity practitioners, understanding these evolving TTPs is critical for improving detection capabilities, threat intelligence sharing, and defensive strategies against nation-state actors targeting defense, aerospace, and government sectors.
Technical Details
- SSH Tunneling Utility: A reverse SSH tunneling tool disguised as the Windows Terminal Server SDK API, establishing SSH connections to operator infrastructure at 172.86.98[.]113 on port 443, enabling covert command-and-control communication
- TWOSTROKE-like C++ Backdoor: A new backdoor implant that mimics wtsapi32.dll, uses three hard-coded C2 servers over HTTPS, and upon receiving commands, spawns worker threads to execute operations including file download/upload, binary/DLL execution, host information gathering, directory listing, and file deletion
- Tortoiseshell Infrastructure: Extensive infrastructure uncovered spanning multiple European and Middle Eastern countries, linked to the Charming Kitten cluster, indicating expanded operational reach
- Related Malware Families: Previous Kaspersky findings include NightLedger Windows backdoor and custom WebSocket tunnelers (BridgeHead and ArcBridge), demonstrating a diverse and growing arsenal of persistence and exfiltration tools
- Social Engineering Campaigns: Nimbus Manticore continues its Dream Job campaign, delivering malware under the pretext of employment opportunities targeting defense, aerospace, IT service providers, and military organizations
Industry Insight
- Organizations operating in or targeting the Middle East and Europe should enhance monitoring for wtsapi32.dll anomalies and unexpected SSH connections on port 443, as these are key indicators of compromise for Nimbus Manticore and Tortoiseshell operations
- Threat intelligence teams should prioritize tracking infrastructure overlaps between Nimbus Manticore, Tortoiseshell, and Charming Kitten clusters, as shared tooling and infrastructure suggest coordinated campaigns with expanding scope
- Security awareness programs should reinforce scrutiny of job opportunity-themed phishing attempts, particularly in defense and aerospace sectors, as social engineering remains a primary initial access vector for this threat actor
Disclaimer: The above content is generated by AI and is for reference only.