AI Security AI安全 5h ago Updated 1h ago 更新于 1小时前 42

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Nimbus Manticore 扩展工具集,新增 TWOSTROKE 风格后门和 SSH 隧道工具

Group-IB uncovered new infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored APT group affiliated with the IRGC Researchers discovered an SSH-based reverse tunneling utility masquerading as the Windows Terminal Server SDK API and a C++ backdoor sharing similarities with the previously known TWOSTROKE implant The backdoor mimics wtsapi32.dll, connects to one of three hard-coded C2 servers over HTTPS, and supports file manipulation, DLL loading, Nimbus Manticore是伊朗IRGC关联的APT组织,2026年高度活跃,与Tortoiseshell组织存在关联。 发现新型SSH隧道工具和类似TWOSTROKE的C++后门程序,后者伪装成wtsapi32.dll。 后门支持文件操作、命令执行、持久化等功能,通过硬编码C2服务器建立HTTPS连接。 威胁基础设施扩展至欧洲和中东地区,目标范围扩大。 该组织持续演进工具链,采用社会工程学攻击(如Dream Job活动)投递恶意软件。

62
Hot 热度
65
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • Group-IB uncovered new infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored APT group affiliated with the IRGC
  • Researchers discovered an SSH-based reverse tunneling utility masquerading as the Windows Terminal Server SDK API and a C++ backdoor sharing similarities with the previously known TWOSTROKE implant
  • The backdoor mimics wtsapi32.dll, connects to one of three hard-coded C2 servers over HTTPS, and supports file manipulation, DLL loading, command execution, and persistence mechanisms
  • Tortoiseshell infrastructure was found spanning Europe and the Middle East, suggesting an expanded targeting profile beyond previous operations
  • These findings complement Kaspersky's recent report on NightLedger backdoor and custom WebSocket tunnelers (BridgeHead and ArcBridge), indicating a steadily evolving toolset

Why It Matters

This discovery highlights the rapid evolution of Iranian state-sponsored threat actors and their increasing sophistication in tool development and infrastructure expansion. For AI and cybersecurity practitioners, understanding these evolving TTPs is critical for improving detection capabilities, threat intelligence sharing, and defensive strategies against nation-state actors targeting defense, aerospace, and government sectors.

Technical Details

  • SSH Tunneling Utility: A reverse SSH tunneling tool disguised as the Windows Terminal Server SDK API, establishing SSH connections to operator infrastructure at 172.86.98[.]113 on port 443, enabling covert command-and-control communication
  • TWOSTROKE-like C++ Backdoor: A new backdoor implant that mimics wtsapi32.dll, uses three hard-coded C2 servers over HTTPS, and upon receiving commands, spawns worker threads to execute operations including file download/upload, binary/DLL execution, host information gathering, directory listing, and file deletion
  • Tortoiseshell Infrastructure: Extensive infrastructure uncovered spanning multiple European and Middle Eastern countries, linked to the Charming Kitten cluster, indicating expanded operational reach
  • Related Malware Families: Previous Kaspersky findings include NightLedger Windows backdoor and custom WebSocket tunnelers (BridgeHead and ArcBridge), demonstrating a diverse and growing arsenal of persistence and exfiltration tools
  • Social Engineering Campaigns: Nimbus Manticore continues its Dream Job campaign, delivering malware under the pretext of employment opportunities targeting defense, aerospace, IT service providers, and military organizations

Industry Insight

  • Organizations operating in or targeting the Middle East and Europe should enhance monitoring for wtsapi32.dll anomalies and unexpected SSH connections on port 443, as these are key indicators of compromise for Nimbus Manticore and Tortoiseshell operations
  • Threat intelligence teams should prioritize tracking infrastructure overlaps between Nimbus Manticore, Tortoiseshell, and Charming Kitten clusters, as shared tooling and infrastructure suggest coordinated campaigns with expanding scope
  • Security awareness programs should reinforce scrutiny of job opportunity-themed phishing attempts, particularly in defense and aerospace sectors, as social engineering remains a primary initial access vector for this threat actor

TL;DR

  • Nimbus Manticore是伊朗IRGC关联的APT组织,2026年高度活跃,与Tortoiseshell组织存在关联。
  • 发现新型SSH隧道工具和类似TWOSTROKE的C++后门程序,后者伪装成wtsapi32.dll。
  • 后门支持文件操作、命令执行、持久化等功能,通过硬编码C2服务器建立HTTPS连接。
  • 威胁基础设施扩展至欧洲和中东地区,目标范围扩大。
  • 该组织持续演进工具链,采用社会工程学攻击(如Dream Job活动)投递恶意软件。

为什么值得看

该情报揭示了伊朗国家支持黑客组织的最新技术演进,对网络安全从业者具有重要参考价值,有助于提升对APT威胁的检测和防御能力。同时,恶意软件伪装成合法系统组件的趋势,对依赖传统签名检测的AI安全系统提出挑战。

技术解析

  • SSH隧道工具伪装为Windows Terminal Server SDK API,连接C2服务器172.86.98.113:443,实现隐蔽通信。
  • C++后门程序与TWOSTROKE相似,伪装成wtsapi32.dll,硬编码三个C2服务器,通过HTTPS接收指令。
  • 后门功能包括系统信息收集、DLL加载、文件上传下载、目录列表、命令执行和文件删除,通过创建worker线程执行命令。
  • 基础设施与Kaspersky报告的NightLedger后门及BridgeHead/ArcBridge WebSocket隧道器存在关联,显示工具链协同。
  • 攻击活动结合社会工程学(如虚假招聘邮件),提高初始访问成功率。

行业启示

  • APT组织工具链持续迭代,建议采用行为分析和威胁情报共享机制,而非仅依赖静态签名检测。
  • 恶意软件深度伪装系统组件,需加强端点检测与响应(EDR)解决方案,并监控异常网络行为。
  • 中东和欧洲成为重点攻击目标,相关机构应提升网络安全防护等级,并关注供应链安全。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究