TechNewsReel
Live

Iranian APT Nimbus Manticore Deploys New C++ Backdoor and SSH Tunneler

Group-IB researchers reveal the IRGC-affiliated group has expanded its espionage arsenal with a backdoor mirroring TWOSTROKE capabilities.

TechNewsReel Newsroom · August 26, 2026

Cybersecurity researchers at Group-IB have identified a significant expansion in the toolset used by Nimbus Manticore, an Iranian state-sponsored hacking group. The group has deployed a new C++ backdoor and a specialized SSH tunneler to enhance its cyber espionage operations across Europe and the Middle East.

According to Group-IB, the newly discovered backdoor possesses functionality similar to the TWOSTROKE malware, designed to provide attackers with persistent access to compromised systems. Alongside this backdoor, the group is utilizing a specialized SSH tunneler to facilitate the secure movement of data and command-and-control traffic. These tools allow the group to maintain a stealthy presence while exfiltrating sensitive information from targeted networks.

The Iranian Cyber Landscape

Nimbus Manticore is an Advanced Persistent Threat (APT) group affiliated with the Islamic Revolutionary Guard Corps (IRGC). This expansion is part of a broader strategic trend where Iranian state-sponsored actors develop and deploy sophisticated custom malware to target strategic interests. By evolving their infrastructure, these groups can better evade detection while maintaining long-term access to sensitive networks, often tailoring their approach to the specific security posture of the victim.

Implications for Persistence

The adoption of TWOSTROKE-like capabilities marks a tactical evolution in how Nimbus Manticore maintains its presence within a target environment. The use of a C++ backdoor suggests a move toward more robust, performant tools that can be customized for specific victim environments. When paired with a specialized SSH tunneler, the group increases its ability to exfiltrate data discreetly, significantly raising the risk for targeted government and corporate organizations that may lack visibility into encrypted tunnel traffic.

Future Outlook

Security teams are advised to monitor for the specific indicators of compromise associated with this new toolset. While the core functionality of the backdoor has been identified, the full extent of the group's current target list remains under investigation. Analysts will be watching for further iterations of this C++ framework to determine if Nimbus Manticore is shifting its focus toward new geographic regions or specific industrial sectors, as the group continues to refine its ability to bypass modern endpoint detection and response systems.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.