AI Weekly Malaysia

Back to items Summaries

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

ID
18274
Status
summarized
Published
26 Aug 2026, 11:35 PM
Fetched
27 Aug 2026, 1:49 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.0
Created
27 Aug 2026, 1:51 AM
Tags
Audience
developers

What happened

Group-IB researchers uncovered new infrastructure and malware tied to Nimbus Manticore, an Iranian IRGC-affiliated APT also tracked under names like GalaxyGato and UNC1549. The findings include a reverse SSH tunneling tool masquerading as the Windows Terminal Server SDK API (connecting to 172.86.98[.]113 on port 443) and a C++ backdoor overlapping with the known TWOSTROKE implant, suggesting expanded targeting across the Middle East and Europe.

Why it matters

This is targeted cyber espionage against defense, aerospace, and IT service providers in the Middle East and U.S. — not relevant to builders shipping AI, agents, or SaaS. No action required for this audience unless you operate infrastructure in the targeted sectors or regions.

Discussion angle

Skip this one for the weekly segment unless a member works in defense/aerospace IT; the SSH tunneling technique masquerading as a Windows SDK binary is a notable tradecraft detail but not actionable for general builders.

Top