Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

August 26, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Defense, aerospace, and IT service providers
Incident: Discovery of expanded infrastructure and new custom malware used by Nimbus Manticore.
Impact: Long-term persistent access and espionage capabilities within critical infrastructure and government sectors.
Attacker: Nimbus Manticore
Analysis: The threat group Nimbus Manticore is utilizing an evolved toolset including an SSH-based tunneler and a TWOSTROKE-like backdoor to maintain stealthy persistence. These tools masquerade as legitimate Windows SDK components to evade detection. The expanded infrastructure indicates a broadening geographic focus toward European targets.
Recommendations: Monitor for unusual SSH connections on port 443 and unexpected traffic to known IRGC-linked infrastructure.; Implement strict endpoint monitoring for unauthorized DLL loads mimicking wtsapi32.dll.; Educate staff on social engineering tactics, specifically job-themed phishing lures.
Source: Group-IB

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *