Fast Facts
- Iranian-backed group Nimbus Manticore has expanded its infrastructure across Europe and the Middle East, targeting defense, aerospace, and military sectors with sophisticated malware, including a new C++ backdoor similar to TWOSTROKE.
- The group deploys customized web tunnelers and SSH-based tools that masquerade as legitimate system components, enabling persistent, covert access to compromised networks.
- Their evolving toolkit allows for remote command execution, file management, and data exfiltration, posing significant espionage threats to high-value regional and international organizations.
Threat Overview, Attack Techniques, and Targets
Cybersecurity researchers have found new information about Nimbus Manticore, an Iranian state-sponsored hacking group linked to the IRGC. This group is active in cyber espionage in 2026 and is connected to other known groups like Tortoiseshell and Charming Kitten. Nimbus Manticore uses social engineering campaigns, such as offering fake job opportunities, to deliver malware.
They have expanded their infrastructure across Europe and the Middle East. The group employs sophisticated tools, including a reverse SSH tunneler that appears as the Windows Terminal Server SDK API. They also use a backdoor similar to TWOSTROKE, a C++ malware that can collect system info, load DLL files, manipulate files, and stay persistent on infected systems. Their targets mainly include military, defense, aerospace, and IT organizations in the Middle East and other regions.
Additionally, they use WebSocket tunnelers like BridgeHead and ArcBridge to maintain remote access. This expands their attack capabilities and targeting scope. The group’s activities show an ongoing effort to improve and adapt their attack techniques.
Impact, Security Implications, and Remediation Guidance
The use of advanced malware like the TWOSTROKE-like backdoor and SSH tunneler allows Nimbus Manticore to gain sustained access to targeted networks. This poses a serious risk of cyber espionage and data theft. Their infrastructure’s widespread presence increases the chance of infiltration into government, military, and critical organizations in the Middle East and Europe.
The threat’s evolving methods can bypass traditional security measures. This makes it important for organizations to strengthen their defenses against complex malware and persistent threats.
To address these risks, organizations should consult with their security vendors or authorities to get specific remediation guidance. Updating security systems, monitoring network traffic for unusual SSH activity, and applying latest patches are recommended steps. However, detailed steps should be obtained from trusted cybersecurity sources or relevant vendors to ensure proper response.
Stay Ahead with the Latest Tech Trends
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
