Iran-Linked Tortoiseshell Adds Backdoor and SSH Tunnel to Malware Toolset
This digest was compiled by AI from multiple sources — links to the originals are below.
Group-IB identified a reverse SSH tunneling utility and a C++ backdoor linked to the Iranian state-sponsored group Tortoiseshell, also tracked as Nimbus Manticore. The malware, disguised as wtsapi32.dll, enables command execution and file transfer via hardcoded C2 servers. Newly discovered infrastructure suggests expanded targeting across Europe and the Middle East.
Key Facts
- Group-IB published its analysis of Tortoiseshell's expanded toolset on August 26, 2026.
- The reverse SSH tunneling utility was disguised as the Windows Terminal Server API DLL wtsapi32.dll.
- The C++ backdoor shares similarities with the TWOSTROKE malware documented by Google Threat Intelligence Group in late 2025.
- Two domains, locat[.]sbs and tiktok-u[.]sbs, contained subdomains referencing UAE, Saudi Arabia, the UK, Belgium, Canada, Australia, and Japan.
- Tortoiseshell has been active since at least July 2018, targeting defense, aerospace, IT service providers, and military organizations.
Malware Toolset Expansion
Group-IB identified a reverse SSH tunneling utility disguised as wtsapi32.dll, which forward-exported legitimate functions while using Windows' OpenSSH client to connect to Tortoiseshell infrastructure. The resulting reverse tunnel could redirect traffic from the command-and-control server into the compromised network. Group-IB said the behavior aligned with techniques previously documented by Google Threat Intelligence Group for UNC1549. A second sample was a C++ backdoor that Group-IB said showed similarities to the TWOSTROKE malware previously documented by GTIG in late 2025. The backdoor established HTTPS communications with multiple hardcoded C2 servers and generated a unique identifier from the victim's fully qualified hostname.
Infrastructure and Targeting
Group-IB identified infrastructure connected to a previously known Tortoiseshell C2 domain. Two domains, locat[.]sbs and tiktok-u[.]sbs, resolved to related servers and contained subdomains using country or regional identifiers including UAE, Saudi Arabia, the UK, Belgium, Canada, Australia and Japan. The infrastructure could indicate an expanded targeting profile covering Middle Eastern and European countries, although Group-IB stressed that its actual use remained unclear because researchers had not identified related malware samples. Group-IB also noted that the servers remained in use after the tiktok-u[.]sbs domain was suspended by its registrar, with historical DNS data showing that its subdomains had previously resolved to the same servers as those associated with locat[.]sbs.
Actor Attribution and History
Group-IB described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore, also known as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549, is assessed to be linked to Tortoiseshell, which is part of the Charming Kitten cluster. Tortoiseshell has been active since at least July 2018, mainly targeting defense, aerospace, IT service providers, and military organizations in the Middle East and the U.S. Nimbus Manticore also has a history of orchestrating its own version of the Dream Job campaign to deliver malware under the pretext of job opportunity-themed social engineering attacks.
2 sources
Iran-Linked Tortoiseshell Adds Backdoor and SSH Tunnel to Malware Toolset



