<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler]]></title><description><![CDATA[<p dir="auto">New analysis from Group-IB has uncovered fresh infrastructure and previously unseen malware tied to <strong>Nimbus Manticore</strong>, an Iranian state-sponsored hacking group operating under the Islamic Revolutionary Guard Corps (IRGC). The researchers describe the group as one of the most active Iranian APT collectives in 2026.</p>
<p dir="auto">The newly documented toolset includes a backdoor that shares behavioral similarities with <strong>TWOSTROKE</strong>, a known malware family, alongside a dedicated SSH tunneler utility. These additions suggest the group is refining its operational toolkit for stealthier persistence and more flexible command-and-control routing.</p>
<p dir="auto">Key technical details from the report:</p>
<ul>
<li>The TWOSTROKE-like backdoor is designed to maintain covert access on compromised hosts, using periodic beaconing and encrypted communications to avoid detection.</li>
<li>The SSH tunneler enables the attackers to pivot through victim networks, masking their true origin and establishing secure channels to internal resources.</li>
<li>Group-IB linked these tools to Nimbus Manticore's broader campaigns, which have historically targeted critical infrastructure, government entities, and telecommunications sectors.</li>
<li>The infrastructure overlaps with previously observed Nimbus Manticore operations, reinforcing attribution to the IRGC-affiliated group.</li>
</ul>
<p dir="auto">Organizations should review their network logs for unusual SSH tunneling activity or beaconing traffic that matches these behavioral indicators. Given the group's track record, immediate patching and lateral movement monitoring are advised for high-value targets.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Are any of you already seeing SSH tunneling anomalies in your environments that could line up with this behavior?</p>
]]></description><link>https://xploitlk.com/topic/115/nimbus-manticore-expands-toolset-with-twostroke-like-backdoor-and-ssh-tunneler</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 15:04:29 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/115.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 27 Aug 2026 04:30:26 GMT</pubDate><ttl>60</ttl></channel></rss>