Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Nimbus Manticore Expands Toolset with Advanced Malware Capabilities and Enhanced Stealth


Nimbus Manticore, a sophisticated Iranian state-sponsored hacking group, has recently expanded its toolset with the introduction of a TWOSTROKE-like backdoor and an advanced SSH-based tunneling utility. This development underscores the group's ongoing commitment to evolving its malware capabilities and enhancing its stealth capabilities.

  • Nimbus Manticore, an Iranian state-sponsored hacking group, has expanded its toolset with a TWOSTROKE-like backdoor and an advanced SSH-based tunneling utility.
  • The group's malware targets defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S.
  • The newly discovered malware shares similarities with the TWOSTROKE backdoor and includes a reverse SSH tunneling tool and a C++ backdoor.
  • The malware's advanced capabilities and enhanced stealth capabilities make it a significant concern for organizations in the affected regions.
  • The group's ongoing efforts demonstrate a threat actor that is steadily evolving its toolset and adapting its techniques to maintain access across a growing number of targets.



  • Nimbus Manticore, a sophisticated Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC), has recently expanded its toolset with the introduction of a TWOSTROKE-like backdoor and an advanced SSH-based tunneling utility. This development underscores the group's ongoing commitment to evolving its malware capabilities and enhancing its stealth capabilities.

    According to a recent analysis published by Group-IB, a Singaporean cybersecurity company, Nimbus Manticore has been actively involved in the development of malware tools and has been linked to several other threat actors, including Tortoiseshell and the Charming Kitten cluster. The group's malware has been identified as targeting defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S.

    The newly discovered malware, which includes a reverse SSH tunneling tool and a C++ backdoor, shares similarities with the TWOSTROKE backdoor already attributed to Nimbus Manticore. The backdoor, which mimics the Windows terminal server SDK DLL, allows for system information collection, DLL loading, file manipulation, and persistence. It also enables the malware to download/upload files, execute a binary or DLL, gather host information, list directories, and delete specific files.

    The discovery of this malware highlights the threat actor's continued efforts to adapt and evolve its tactics, techniques, and procedures (TTPs) to maintain access across a growing number of targets. Group-IB researchers noted that the identification of infrastructure targeting Middle Eastern and European countries, alongside the continued development of tools such as the TWOSTROKE backdoor and SSH-based tunneling utilities, demonstrates a threat actor that is steadily evolving its toolset and adapting its techniques to maintain access across a growing number of targets.

    The malware's advanced capabilities and enhanced stealth capabilities make it a significant concern for organizations in the affected regions. The use of SSH-based tunneling utilities, in particular, allows the malware to maintain persistent access to compromised hosts in attacks aimed at entities across the Middle East, Africa, and South Asia.

    The findings of this analysis are particularly relevant in light of recent reports from other cybersecurity companies, including Kaspersky, which detailed the threat actor's use of a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge. These tools were identified as having an aim to maintain persistent access to compromised hosts in attacks aimed at entities across the Middle East, Africa, and South Asia.

    In conclusion, the recent expansion of Nimbus Manticore's toolset with advanced malware capabilities and enhanced stealth capabilities underscores the group's ongoing commitment to evolving its malware capabilities and enhancing its stealth capabilities. The discovery of this malware highlights the need for organizations in the affected regions to remain vigilant and take proactive measures to protect themselves against the threat actor's ongoing efforts.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Nimbus-Manticore-Expands-Toolset-with-Advanced-Malware-Capabilities-and-Enhanced-Stealth-ehn.shtml

  • https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html


  • Published: Wed Aug 26 16:49:51 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us