New Malware Tools Reveal Advanced Tactics
Cybersecurity researchers have uncovered new malware and infrastructure linked to Nimbus Manticore, an Iranian state-sponsored hacking group tied to the Islamic Revolutionary Guard Corps. The discovery was made by Group-IB in an analysis published on August 26, 2026, revealing previously undocumented tools used in cyber espionage campaigns. The findings highlight the group’s evolving capabilities and persistent focus on intelligence gathering.
Latest news
Apple unveils new iPhone lineup next week
NordVPN Browser Extension Gets Redesigned Interface and Smarter Search
Ugreen's DXP6800 Pro NAS Benefits From Additional Network Upgrade
Google Gemini Error Strands Climbers on Mount ShastaThe newly identified malware includes a backdoor resembling the TWOSTROKE framework and an SSH tunneler designed to maintain covert access to compromised networks. These tools allow attackers to exfiltrate data, move laterally within systems, and evade detection by mimicking legitimate network traffic. Group-IB noted that the infrastructure supporting these tools shows signs of long-term development and testing, suggesting a sustained investment in offensive cyber capabilities. The malware has been observed in operations targeting government and telecommunications sectors in the Middle East and South Asia.
How Does This Affect Regional Cybersecurity?
The expansion of Nimbus Manticore’s toolkit raises concerns about the group’s ability to conduct prolonged surveillance and disrupt critical services. Security experts warn that the use of legitimate protocols like SSH for tunneling makes detection more difficult for traditional defenses. This trend reflects a broader shift among state-backed actors toward stealthy, low-noise techniques that blend into normal network activity. Organizations are urged to monitor for anomalous SSH connections and review authentication logs for signs of unauthorized access.
What is Nimbus Manticore known for? Nimbus Manticore is an Iranian hacking group linked to the IRGC, primarily engaged in cyber espionage against governmental and telecom targets in regional conflicts.
Frequently Asked Questions
Why is the SSH tunneler significant? The SSH tunneler enables stealthy communication with infected systems by hiding malicious traffic within encrypted channels commonly trusted by networks, reducing the chance of detection.
Are these tools currently active in attacks? Yes, Group-IB confirmed that the newly discovered malware and infrastructure have been observed in recent operations, indicating active deployment.
Comments
Leave a comment