Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
- ID
- 18274
- Status
- summarized
- Published
- 26 Aug 2026, 11:35 PM
- Fetched
- 27 Aug 2026, 1:49 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 27 Aug 2026, 1:51 AM
- Tags
- Audience
- developers
What happened
Group-IB researchers uncovered new infrastructure and malware tied to Nimbus Manticore, an Iranian IRGC-affiliated APT also tracked under names like GalaxyGato and UNC1549. The findings include a reverse SSH tunneling tool masquerading as the Windows Terminal Server SDK API (connecting to 172.86.98[.]113 on port 443) and a C++ backdoor overlapping with the known TWOSTROKE implant, suggesting expanded targeting across the Middle East and Europe.
Why it matters
This is targeted cyber espionage against defense, aerospace, and IT service providers in the Middle East and U.S. — not relevant to builders shipping AI, agents, or SaaS. No action required for this audience unless you operate infrastructure in the targeted sectors or regions.
Discussion angle
Skip this one for the weekly segment unless a member works in defense/aerospace IT; the SSH tunneling technique masquerading as a Windows SDK binary is a notable tradecraft detail but not actionable for general builders.