Interestana
Home/News/Nimbus Manticore Adds TWOSTROKE Backdoor, SSH Tunneler
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Nimbus Manticore Adds TWOSTROKE Backdoor, SSH Tunneler

Nimbus Manticore Adds TWOSTROKE Backdoor, SSH Tunneler

Cybersecurity researchers have uncovered new malware and expanded infrastructure linked to Nimbus Manticore, an Iranian state-sponsored hacking group identified as being affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in an analysis published on March 18, 2026, characterized Nimbus Manticore as one of the most active Iranian Advanced Persistent Threat (APT) groups observed during 2026. The group, also known by other monikers, has been observed employing sophisticated techniques for espionage and data exfiltration.

The newly identified tools include a backdoor that exhibits similarities to the TWOSTROKE malware, a sophisticated implant previously attributed to other APT groups. This backdoor likely allows Nimbus Manticore operatives to gain persistent access to compromised systems, execute arbitrary commands, and exfiltrate sensitive data. The analysis further details the use of an SSH (Secure Shell) tunneler, a utility that enables attackers to create encrypted communication channels between compromised machines and their command-and-control (C2) infrastructure. This technique is crucial for maintaining covert access and evading detection by security monitoring systems.

Group-IB's research highlights that Nimbus Manticore has been actively developing and deploying these new capabilities throughout 2026. The group's operational tempo and the sophistication of their toolset underscore their significance as a persistent threat actor. Their targets are believed to include government entities, critical infrastructure, and organizations within sectors such as telecommunications and energy, primarily in the Middle East and potentially extending to other regions. The IRGC affiliation suggests a strong backing and strategic alignment with Iranian state objectives, focusing on intelligence gathering and cyber espionage.

The discovery of these new tools by Group-IB provides critical insights into Nimbus Manticore's evolving tactics, techniques, and procedures (TTPs). The use of a TWOSTROKE-like backdoor and an SSH tunneler indicates a focus on stealth, persistence, and robust command-and-control mechanisms. Cybersecurity professionals are advised to enhance their defenses against these specific TTPs, including strengthening endpoint detection and response (EDR) capabilities, monitoring for unusual SSH activity, and ensuring robust network segmentation to limit the lateral movement of attackers. The ongoing analysis by Group-IB aims to provide a comprehensive understanding of Nimbus Manticore's operations to aid in attribution and mitigation efforts.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next