Nimbus Manticore Expands Toolset With New Backdoor Targeting Middle East and Europe
Group-IB has uncovered new infrastructure and malware linked to Nimbus Manticore, an Iranian state-sponsored APT group expanding its targeting across the Middle East and Europe.

A dimly lit server room with an illuminated network switch panel, representing covert infrastructure used in a cyber espionage campaign
Cybersecurity researchers have uncovered new infrastructure and previously undocumented malware tied to Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps. The findings, published today by Group-IB, add to a growing body of mena cyber security news this year documenting how persistently this particular actor continues refining its toolset against targets across the region.
Group-IB describes Nimbus Manticore as among the most active Iranian advanced persistent threat groups in 2026. The actor, also tracked under the names GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail and UNC1549, is assessed as linked to Tortoiseshell, itself part of the broader Charming Kitten cluster. Tortoiseshell has been active since at least July 2018, historically targeting defence, aerospace, IT service providers and military organisations across the Middle East and the United States, a persistence that underscores why staying current with gulf cyber security news on this actor's evolving techniques matters for security teams well beyond a single incident response cycle.
The specific tradecraft documented in this latest research gives defenders concrete detection opportunities rather than abstract warnings. Group-IB uncovered extensive Tortoiseshell infrastructure spanning both Europe and the Middle East, alongside two newly identified tools: an SSH-based tunnelling utility and a C++ backdoor sharing characteristics with TWOSTROKE, a backdoor previously attributed to the same actor. Researchers Mansour Alhmoud and Mohamed Emam noted that the discovered infrastructure potentially suggests an expanded targeting profile focused on Middle Eastern countries alongside European ones, a detail worth flagging directly to any organisation currently relying on regional threat intelligence sharing to calibrate its own monitoring priorities.
The technical details behind these two tools illustrate a deliberate effort to blend into legitimate system activity rather than stand out as obviously malicious. The reverse SSH tunnelling tool masquerades as the Windows Terminal Server SDK API while quietly establishing an SSH connection to attacker-controlled infrastructure over port 443, a port choice that lets the traffic hide in plain sight alongside routine encrypted web traffic. The second tool, the TWOSTROKE-overlapping backdoor, mimics a legitimate Windows terminal server DLL and uses one of three hard-coded command-and-control servers to establish an HTTPS connection and await instructions. Once a command arrives, the backdoor spins up a new worker thread to execute it, supporting file upload and download, binary or DLL execution, host information gathering, directory listing and targeted file deletion, a functional profile consistent with an actor conducting sustained reconnaissance and data collection rather than opportunistic, smash-and-grab intrusion.
This latest disclosure builds directly on a Kaspersky report published in July, which detailed the same actor's use of a separate Windows backdoor called NightLedger, alongside two custom WebSocket tunnellers named BridgeHead and ArcBridge, deployed specifically to maintain persistent access to compromised hosts across the Middle East, Africa and South Asia. Group-IB's own assessment ties the pattern together plainly: the identification of infrastructure targeting Middle Eastern and European countries, combined with continued development of tools like TWOSTROKE and SSH-based tunnelling utilities, demonstrates a threat actor steadily evolving its toolset and adapting techniques to maintain access across a growing number of targets.
Nimbus Manticore's history extends beyond pure technical tooling into social engineering as well. The group has previously orchestrated its own version of the well-documented Dream Job campaign, using fake job opportunities as a pretext to deliver malware to targets in defence, aerospace and government-adjacent sectors, a technique that continues to succeed globally precisely because it exploits a moment of genuine professional interest rather than obvious urgency or fear.
For security teams across defence, aerospace, telecommunications and government-adjacent sectors specifically, this disclosure offers several concrete, actionable indicators worth building into detection rules immediately. Unexpected outbound SSH connections over port 443 masquerading as legitimate Windows components, unfamiliar DLLs mimicking wtsapi32.dll, and any process attempting to establish HTTPS connections to unfamiliar external infrastructure while spawning worker threads should all be treated as high-priority investigation triggers rather than routine noise. Organisations weighing whether their existing EDR platform is tuned to catch this specific pattern of DLL impersonation and tunnelled command-and-control traffic should treat this report as a direct prompt to verify that coverage now, rather than after the next disclosure names a fresh variant, and should confirm their SIEM platform is actually correlating the relevant log sources rather than simply ingesting them.
The broader lesson from Nimbus Manticore's trajectory, from NightLedger and its WebSocket tunnellers in July to this new SSH tunnelling tool and TWOSTROKE variant today, is that IRGC-affiliated actors are not pursuing a single static toolkit against the region. They are iterating deliberately, refining evasion techniques and expanding infrastructure footprint in measured steps. Regional organisations that have already invested in identity and access management discipline and layered SIEM detection capability are better positioned to catch this kind of incremental tooling evolution before it matures into a full intrusion, but only if that monitoring is actively updated against newly published indicators like the ones Group-IB has released today. Static defences against an actively evolving actor are, by definition, already falling behind.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.