Nimbus Manticore, an IRGC-affiliated threat actor, has evolved its 2026 espionage operations by deploying a modified TWOSTROKE-variant backdoor and a custom Reverse SSH Tunneling utility to bypass network perimeter defenses. These tools, alongside the Minifast backdoor, utilize SSH-based exfiltration and tunneling protocols to establish persistent, covert Command and Control (C2) channels. The group leverages infrastructure historically linked to the Tortoiseshell actor profile to target high-value geopolitical entities, shifting toward a modular architecture to evade signature-based detection and increase operational tempo.
-
Campaign Overview: Strategic Evolution
- IRGC-affiliated actor Nimbus Manticore is shifting toward modular toolsets to enhance espionage capabilities in 2026.
- Transition from legacy tools to customized variants indicates increased resource investment and development sophistication.
- Operations focus on high-value geopolitical targets relevant to Iranian state interests.
-
Technical Analysis: The Malware Toolset
- Deployment of a TWOSTROKE-variant backdoor, utilizing modified code to evade traditional antivirus and EDR signatures.
- Integration of the Minifast backdoor, as identified in Broadcom security bulletins, for initial access and persistence.
- Use of customized Reverse SSH Tunneling utilities to encapsulate C2 traffic and mask unauthorized outbound connections.
-
Network Evasion: Reverse SSH Tunneling
- Implementation of reverse tunnels to bypass restrictive firewall egress rules and network perimeter defenses.
- Use of SSH-based exfiltration protocols to blend malicious data transfers with legitimate administrative traffic.
- Strategic reliance on infrastructure previously associated with the Tortoiseshell actor profile for C2 orchestration.
-
Threat Profile and Operational Impact
- Identified as one of the most active Iranian APT groups of 2026, exhibiting an accelerated operational tempo.
- Increased persistence capabilities make the detection of unauthorized outbound tunnels significantly more difficult for SOC teams.
- Evolution toward customized malware suggests a move away from off-the-shelf tools to avoid global threat intelligence tracking.
-
Defensive Actions and Mitigation
- Enforce strict egress filtering to restrict outbound SSH (Port 22) traffic to known, authorized gateways.
- Implement behavioral monitoring for long-duration SSH sessions and unusual data volume spikes to external IPs.
- Deploy updated IOCs and YARA rules specifically targeting TWOSTROKE and Minifast backdoor variants.
Related posts
- techjacksolutions.com — Nimbus Manticore Expands Espionage Toolset With TWOSTROKE-Variant Backdoor and Reverse SSH Tunneling Utility
- feeds.feedburner.com — Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
- SC Media — Nimbus Manticore expands infrastructure and malware arsenal
- Group-ib
- Infosecurity-magazine
- Blog
- Broadcom