Executive Summary

In August 2026, cybersecurity researchers discovered new infrastructure and previously undocumented malware tools used by Nimbus Manticore, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps (IRGC). The threat actor has expanded their arsenal with a TWOSTROKE-like C++ backdoor and an SSH tunneling utility that masquerades as Windows Terminal Server SDK components. Group-IB's analysis revealed extensive infrastructure spanning Europe and the Middle East, indicating an expanded targeting profile beyond their traditional focus on defense, aerospace, and military organizations in the Middle East and United States.

This incident highlights the continued evolution of Iranian APT capabilities and their persistent focus on establishing long-term access to critical infrastructure. As nation-state actors increasingly develop sophisticated toolsets and expand their geographic reach, organizations must prioritize comprehensive network visibility and east-west traffic monitoring to detect lateral movement and command-and-control activities.

Why This Matters Now

Iranian APT groups are rapidly expanding their toolkits and geographic targeting in 2026, with Nimbus Manticore demonstrating advanced persistence techniques that bypass traditional security controls through SSH tunneling and custom backdoors.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The group has deployed a TWOSTROKE-like C++ backdoor and an SSH tunneling utility that masquerades as Windows Terminal Server SDK components for persistent access.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained Nimbus Manticore's lateral movement and C2 communications through segmented network access and controlled egress policies. The attack's blast radius across European and Middle Eastern infrastructure would likely have been substantially reduced.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Malicious payload deployment would likely face restricted network access patterns and limited ability to establish initial footholds across cloud workloads through identity-aware access controls

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Process masquerading attempts would likely encounter segmented privilege boundaries that constrain escalation scope and limit access to critical system resources across isolated workload environments

Lateral Movement

Control: East-West Traffic Security

Mitigation: SSH tunneling operations would likely face significant constraints in cross-regional infrastructure movement due to enforced segmentation policies that limit east-west traffic flows between workloads

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communications to external servers would likely be constrained through comprehensive traffic monitoring and policy enforcement that limits backdoor connectivity to unauthorized external infrastructure

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration operations would likely encounter significant limitations in outbound data transfer capabilities due to controlled egress policies that restrict unauthorized file upload activities

Impact (Mitigations)

Long-term espionage operations would likely be limited to isolated workload segments with substantially reduced blast radius compared to the original multi-country infrastructure compromise achieved by the threat actor

Impact at a Glance

Affected Business Functions

  • Defense Operations
  • Aerospace Engineering
  • IT Service Delivery
  • Military Communications
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of sensitive military and defense contractor information, aerospace technology designs, IT infrastructure details, and operational intelligence. The TWOSTROKE-like backdoor capabilities include system information collection, file manipulation, and persistent access to compromised networks across targeted organizations in the Middle East, Europe, Africa, and South Asia.

Recommended Actions

  • Implement Egress Security & Policy Enforcement to block unauthorized outbound connections to C2 infrastructure like 172.86.98.113:443 and prevent data exfiltration through encrypted channels
  • Deploy Zero Trust Segmentation with identity-based policies to prevent lateral movement across European and Middle Eastern infrastructure using SSH tunneling utilities
  • Enable Multicloud Visibility & Control to detect anomalous HTTPS traffic patterns and suspicious automation characteristic of TWOSTROKE-like backdoor operations
  • Utilize Threat Detection & Anomaly Response capabilities to identify masquerading techniques like fake wtsapi32.dll processes and establish behavioral baselines for legitimate system activity
  • Strengthen Encrypted Traffic inspection capabilities to analyze suspicious HTTPS C2 communications and implement inline IPS with Suricata signatures targeting known Iranian APT malware families

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image