Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels
4 Articles
4 Articles
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka
Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to give operators covert, durable access to compromised internal networks. The research began with public reporting from Kaspersky on Mirage Kitten’s newer malware ecosystem, which included the NightLedger backdoor and WebSocket tunneling tools ArcBridge and BridgeHead. […] This article has been in…
Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor
Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno JavaScript and TypeScript runtime to execute encoded code, helping its activity blend into legitimate software use. Dindoor has appeared as a later-stage payload in spearphishing intrusions. Researchers observed it at U.S. software and banking organizations and at a Canadian non-profit, demonstratin…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium





