Uncategorized

Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels

Iran-linked hackers have expanded an espionage effort with a Windows backdoor and reverse SSH tunnelling utility. The activity is tied to Tortoiseshell, also tracked as Mirage Kitten, UNC1549 and Nimbus Manticore.

The campaign gives operators more ways to retain access after breaking into a network. The tunnelling tool can route traffic from an attacker-controlled server into a victim environment, while the backdoor can run commands, move files and collect details about an infected computer.

Group-IB analysts identified additional malware and infrastructure after enriching published indicators and conducting threat-hunting work.

Their findings suggest that Tortoiseshell is widening its operational footprint across Middle Eastern and European targets.

The group has been active since at least 2018 and has historically focused on defence, aerospace, IT service providers and military organisations.

Its documented entry methods include supply-chain compromise, compromised websites and fake recruitment portals, making user vigilance and layered security important.

Group-IB said in a report shared with Cyber Security News (CSN). The research connects the components to a wider Iranian-linked activity set and underlines the risk to organisations handling strategic or government-adjacent information.

It raises risks for regional defenders facing persistent espionage operations. High-value sectors remain especially exposed.

Iran-Linked Hackers Expand Attacks

One recovered component poses as a normal Windows library named wtsapi32.dll, a file associated with Terminal Server functions. It passes legitimate functions through to avoid suspicion, while quietly launching a reverse SSH connection over port 443 to an operator server.

This is important because the connection begins inside the victim network. Once active, traffic sent to a specified port on the remote server can be channelled back into the compromised environment, helping an intruder reach internal systems without opening an obvious inbound route.

Tortoiseshell C2 server node (Source – Group-IB)

Reverse tunnels have become a recurring way to preserve access after a breach. Readers can compare this approach with reverse tunnel attack concerns, where outbound connections similarly created a path that bypassed expected network boundaries.

The second sample is a C++ implant resembling the TWOSTROKE backdoor reported previously. It also masquerades as wtsapi32.dll and appears designed for DLL search-order hijacking, a method that makes a trusted program load an attacker-controlled library instead of the genuine one.

The backdoor hides key text until runtime, creates a unique identifier from the device hostname, and communicates with hardcoded control servers using HTTPS.

It can receive instructions to upload or steal files, launch programs or shell commands, load a DLL in memory, download files, and list folders.

That reliance on trusted Windows loading behaviour mirrors the technique described in malware abusing DLL search order. For defenders, an unfamiliar wtsapi32.dll beside an application deserves investigation rather than being assumed legitimate.

Infrastructure points to wider reach

Group-IB linked more infrastructure to the operation by pivoting from a known control domain. It found domains and subdomains patterned around country labels, with nodes associated with the United Arab Emirates, Saudi Arabia, the United Kingdom, Belgium, Canada, Australia and Japan.

The researchers cautioned that infrastructure alone cannot prove its final use, since no matching samples were identified for every node.

Still, the geographic naming pattern, coupled with servers retained after one related domain was suspended, indicates preparation that defenders should not ignore.

New IP address linked to a known Tortoiseshell C2 (Source – Group-IB)

The findings reinforce a lesson from APT attacks on RDP servers: persistent groups often maintain more than one route into a network. A secondary tunnel or backdoor can keep an operation alive when the main access method is detected and removed.

Organisations in affected sectors should continuously hunt for unusual DLL side-loading, unknown outbound SSH activity and repetitive HTTPS beaconing.

They should also use endpoint detection tools and focused detection rules, review connections to known infrastructure, and share confirmed sightings with trusted security partners.

Network teams should pay attention to SSH launched from unexpected Windows processes and connections using port 443 that do not behave like ordinary web traffic.

Monitoring these signs alongside SSH-based backdoor warning signs can shorten the time between an intrusion and containment.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
File namewtsapi32.dllName used by both identified malicious DLL samples to masquerade as a legitimate Windows library
MD5 hash07dd28b748656e9e1a870c538d6df68cReverse SSH tunnelling tool
SHA-1 hashe39bb97415978fa3484298735bd020662a51f3abReverse SSH tunnelling tool
SHA-256 hashd23c1b7b917f53e4e5a608e9870e574f7461eead277726249c4acf4a2b0bef4bReverse SSH tunnelling tool
MD5 hashdb58adc4a6c192520ed509b20a928279TWOSTROKE backdoor
SHA-1 hashc0dba95939f7fc1a55b7aa6c132a204f073a981dTWOSTROKE backdoor
SHA-256 hash597c40e0b23f38f30a3c85be0510b14985b2948895819c899e3f3c8f200aa437TWOSTROKE backdoor
IP address172[.]86[.]98[.]113Reverse SSH tunnel server
IP address185[.]66[.]68[.]213Reported Tortoiseshell-linked infrastructure
IP address185[.]253[.]116[.]71Reported Tortoiseshell-linked infrastructure
IP address185[.]253[.]116[.]242Reported Tortoiseshell-linked infrastructure
IP address185[.]253[.]118[.]246Reported Tortoiseshell-linked infrastructure
IP address94[.]126[.]227[.]20Reported Tortoiseshell-linked infrastructure
IP address89[.]44[.]80[.]42uae7 node associated with locat[.]sbs
IP address91[.]193[.]16[.]187Reported Tortoiseshell-linked infrastructure
IP address89[.]44[.]80[.]234uae2 node associated with locat[.]sbs
IP address89[.]44[.]80[.]6uae5 node associated with locat[.]sbs
IP address94[.]126[.]227[.]11Reported Tortoiseshell-linked infrastructure
IP address89[.]44[.]80[.]86Reported Tortoiseshell-linked infrastructure
IP address185[.]253[.]116[.]99uae3 node associated with locat[.]sbs
IP address185[.]253[.]116[.]81IP linked to the known aecert[.]org control domain
IP address89[.]44[.]80[.]168uae1 node associated with locat[.]sbs
IP address95[.]174[.]68[.]199uae4 node associated with locat[.]sbs
IP address185[.]253[.]116[.]166uae6 node associated with locat[.]sbs
Domainneexportfolio[.]comHardcoded TWOSTROKE command-and-control server
Domainneexportfolio[.]azurewebsites[.]netHardcoded TWOSTROKE command-and-control server
Domainneexportfolio[.]eastus[.]cloudapp[.]azure[.]comHardcoded TWOSTROKE command-and-control server
Domainaecert[.]orgKnown Tortoiseshell control domain used for infrastructure pivoting
Domainlocat[.]sbsRelated infrastructure domain with country-themed subdomains
Domaintiktok-u[.]sbsRelated infrastructure domain later suspended by its registrar

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

3 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

3 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago