Executive Summary
In August 2026, cybersecurity researchers discovered new infrastructure and previously undocumented malware tools used by Nimbus Manticore, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps (IRGC). The threat actor has expanded their arsenal with a TWOSTROKE-like C++ backdoor and an SSH tunneling utility that masquerades as Windows Terminal Server SDK components. Group-IB's analysis revealed extensive infrastructure spanning Europe and the Middle East, indicating an expanded targeting profile beyond their traditional focus on defense, aerospace, and military organizations in the Middle East and United States.
This incident highlights the continued evolution of Iranian APT capabilities and their persistent focus on establishing long-term access to critical infrastructure. As nation-state actors increasingly develop sophisticated toolsets and expand their geographic reach, organizations must prioritize comprehensive network visibility and east-west traffic monitoring to detect lateral movement and command-and-control activities.
Why This Matters Now
Iranian APT groups are rapidly expanding their toolkits and geographic targeting in 2026, with Nimbus Manticore demonstrating advanced persistence techniques that bypass traditional security controls through SSH tunneling and custom backdoors.
Attack Path Analysis
Nimbus Manticore (Iranian APT) leveraged Dream Job social engineering campaigns to deliver malware including SSH tunneling tools and TWOSTROKE-like backdoors. The threat actor established persistent C2 infrastructure across Europe and Middle East using reverse SSH tunnels masquerading as Windows Terminal Server SDK, executed reconnaissance and file manipulation commands, and maintained long-term access for espionage operations targeting defense, aerospace, and military organizations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Iranian APT Nimbus Manticore deployed Dream Job social engineering campaigns delivering malicious payloads under the pretext of job opportunities to target defense, aerospace, and military organizations
MITRE ATT&CK® Techniques
Spearphishing Attachment
Process Injection
Ingress Tool Transfer
Registry Run Keys / Startup Folder
Proxy
Exfiltration Over C2 Channel
Software Packing
File and Directory Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Custom Software Security Testing
Control ID: 6.3.2
NYDFS 23 NYCRR 500 – Penetration Testing
Control ID: 500.15
DORA – ICT Third-Party Risk Management
Control ID: Article 11
CISA ZTMM 2.0 – Device Integrity and Compliance
Control ID: Device Security
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Controls Against Malware
Control ID: A.12.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Iranian APT Nimbus Manticore's SSH tunneling tools and TWOSTROKE backdoor specifically target telecom infrastructure for cyber espionage operations.
Defense/Space
Defense organizations face direct targeting from IRGC-affiliated groups using advanced C++ backdoors and persistent access tools for intelligence gathering.
Aviation/Aerospace
Aerospace entities encounter sophisticated malware campaigns including Dream Job social engineering attacks and custom WebSocket tunnelers for system compromise.
Information Technology/IT
IT service providers experience expanded targeting from evolving toolsets including reverse SSH tunneling and HTTPS-based command-and-control infrastructure.
Sources
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunnelerhttps://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.htmlVerified
- Tortoiseshell APT Toolset and Infrastructure Analysishttps://www.group-ib.com/blog/tortoiseshell-apt-toolset-infrastructure/Verified
- Nimbus Manticore Deploys NightLedger Backdoor in Middle East Attackshttps://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.htmlVerified
- Iranian Hackers Deploy MiniFast and BrainCrypt Backdoors in Dream Job Attackshttps://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained Nimbus Manticore's lateral movement and C2 communications through segmented network access and controlled egress policies. The attack's blast radius across European and Middle Eastern infrastructure would likely have been substantially reduced.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Malicious payload deployment would likely face restricted network access patterns and limited ability to establish initial footholds across cloud workloads through identity-aware access controls
Control: Zero Trust Segmentation
Mitigation: Process masquerading attempts would likely encounter segmented privilege boundaries that constrain escalation scope and limit access to critical system resources across isolated workload environments
Control: East-West Traffic Security
Mitigation: SSH tunneling operations would likely face significant constraints in cross-regional infrastructure movement due to enforced segmentation policies that limit east-west traffic flows between workloads
Control: Multicloud Visibility & Control
Mitigation: C2 communications to external servers would likely be constrained through comprehensive traffic monitoring and policy enforcement that limits backdoor connectivity to unauthorized external infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration operations would likely encounter significant limitations in outbound data transfer capabilities due to controlled egress policies that restrict unauthorized file upload activities
Long-term espionage operations would likely be limited to isolated workload segments with substantially reduced blast radius compared to the original multi-country infrastructure compromise achieved by the threat actor
Impact at a Glance
Affected Business Functions
- Defense Operations
- Aerospace Engineering
- IT Service Delivery
- Military Communications
Estimated downtime: 7 days
Estimated loss: N/A
Potential exposure of sensitive military and defense contractor information, aerospace technology designs, IT infrastructure details, and operational intelligence. The TWOSTROKE-like backdoor capabilities include system information collection, file manipulation, and persistent access to compromised networks across targeted organizations in the Middle East, Europe, Africa, and South Asia.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to block unauthorized outbound connections to C2 infrastructure like 172.86.98.113:443 and prevent data exfiltration through encrypted channels
- • Deploy Zero Trust Segmentation with identity-based policies to prevent lateral movement across European and Middle Eastern infrastructure using SSH tunneling utilities
- • Enable Multicloud Visibility & Control to detect anomalous HTTPS traffic patterns and suspicious automation characteristic of TWOSTROKE-like backdoor operations
- • Utilize Threat Detection & Anomaly Response capabilities to identify masquerading techniques like fake wtsapi32.dll processes and establish behavioral baselines for legitimate system activity
- • Strengthen Encrypted Traffic inspection capabilities to analyze suspicious HTTPS C2 communications and implement inline IPS with Suricata signatures targeting known Iranian APT malware families



