Iranian APT Tortoiseshell Expands Infrastructure Into Saudi Arabia and the UAE, Researchers Say

Researchers have identified new Tortoiseshell infrastructure in Saudi Arabia and the UAE, alongside the UK and Belgium, expanding the known footprint of one of Iran's most active APT groups.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
A server room with rows of networking equipment, representing the expansion of Iranian-linked threat actor Tortoiseshell's infrastructure into Saudi Arabia and the UAE

A server room with rows of networking equipment, representing the expansion of Iranian-linked threat actor Tortoiseshell's infrastructure into Saudi Arabia and the UAE

Researchers have identified new infrastructure linked to Tortoiseshell, an Iranian threat actor active since at least 2018, that points to the group expanding its footprint into Saudi Arabia and the UAE alongside new servers in Britain and Belgium, according to a report published this week by cybersecurity firm Group-IB. The group has previously focused its espionage operations on defense, aerospace, technology and military organisations, primarily across the Middle East and the United States.

Group-IB identified two servers, named "uk1" and "uk2," hosted on UK-based IP addresses, alongside separately confirmed Tortoiseshell-linked infrastructure in Belgium, Saudi Arabia and the UAE. Researchers were careful to note that the country-themed naming convention on its own does not confirm who the group is targeting in each location, the purpose of the newly identified infrastructure remains unclear. What the finding does establish is a broadening operational footprint: a group researchers describe as one of the most active Iranian advanced persistent threat groups currently operating is building infrastructure across a wider geographic spread than its historical targeting pattern would suggest.

Alongside the new servers, researchers uncovered fresh malware samples tied to the group, including a backdoor resembling a tool known as TwoStroke, previously documented by Google's threat intelligence team in late 2025. The malware gives attackers broad control over compromised machines: executing commands, downloading and exfiltrating files, inspecting directories, and gathering system information. Researchers also found a tool that establishes a reverse SSH tunnel between infected machines and attacker-controlled infrastructure, a technique that lets attackers route traffic back through a compromised device to reach further into a victim's network while bypassing defences built to block incoming connections.

Tortoiseshell has previously been linked by researchers to operations supporting Iran's Islamic Revolutionary Guard Corps, the same institutional backing attributed to CyberAv3ngers, the group behind the recent US water utility intrusions and UK power plant breach MCW has covered this week, and to Handala, the Iranian-linked threat actor GCC enterprises cannot afford to ignore. Tortoiseshell is a distinct group from both, with its own toolset and targeting history focused on defense, aerospace and technology rather than industrial control systems. It's also worth distinguishing from a third IRGC-linked actor active in the same sectors this year, Nimbus Manticore, which was found this year deploying an AI-built MiniFast backdoor against aviation targets specifically in Saudi Arabia and the UAE. Tortoiseshell's emergence alongside those campaigns this month reinforces a broader pattern, one that extends beyond Iran-linked activity specifically: state-backed groups more broadly are simultaneously upgrading tooling and expanding geographic reach, as MCW has also tracked with a Chinese APT's recent overhaul of the BPFdoor backdoor targeting telecoms and critical infrastructure across the Middle East and beyond, rather than any single campaign representing an isolated incident.

For GCC-based defense, aerospace and technology organisations specifically, confirmed Tortoiseshell infrastructure inside Saudi Arabia and the UAE is a direct signal rather than a distant one. Group-IB's own framing, that the infrastructure's purpose and targets remain unconfirmed, means the practical response for regional security teams is monitoring and threat hunting against known Tortoiseshell indicators, rather than waiting for formal notification of a specific breach. The group's historical focus on defense and aerospace targets makes this particularly relevant for GCC entities in those sectors, which sit at the intersection of exactly the industries Tortoiseshell has targeted before and the two countries where its new infrastructure has just been confirmed.

Attribution to the Iranian state, as with the other Iran-linked campaigns under scrutiny this month, remains researcher assessment based on historical pattern and known IRGC ties rather than a formal government attribution. No government agency has issued an official statement connecting this specific infrastructure discovery to state-directed activity. For security teams tracking the broader picture, the more important takeaway may be less about attribution certainty and more about scope: a well-established Iranian APT group is demonstrably building infrastructure in new geographies at the same time several other Iran-linked campaigns are drawing fresh scrutiny, a clustering worth watching rather than treating each discovery in isolation.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.