FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Nimbus Manticore Espionage Toolset Expansion: TWOSTROKE-Variant and Reverse SSH Tunneling

Nimbus Manticore, an IRGC-affiliated threat actor, has evolved its 2026 espionage operations by deploying a modified TWOSTROKE-variant backdoor and a custom Reverse SSH Tunneling utility to bypass network perimeter defenses. These tools, alongside the Minifast backdoor, utilize SSH-based exfiltration and tunneling protocols to establish persistent, covert Command and Control (C2) channels. The group leverages infrastructure historically linked to the Tortoiseshell actor profile to target high-value geopolitical entities, shifting toward a modular architecture to evade signature-based detection and increase operational tempo.


LINK COPIED TO CLIPBOARD