Threat Intelligence

Iranian State-Backed Hackers Add New Backdoor and Tunneling Tool to Arsenal

The Hacker News · 27 Aug 2026
Key Takeaway Even small businesses should monitor for unusual outbound network connections, as state-sponsored actors often use tunneling tools to quietly move data through trusted-looking traffic.

Cybersecurity researchers at Group-IB have identified new malware tools and infrastructure tied to Nimbus Manticore, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps (IRGC). The group has been named one of the most active Iranian advanced persistent threat (APT) actors observed in 2026.

According to the analysis, Nimbus Manticore has expanded its toolkit with a previously undocumented backdoor resembling a known malware family called TWOSTROKE, along with a tool designed to tunnel traffic over SSH connections. These additions suggest the group is continuing to invest in new capabilities for covert access and data exfiltration from compromised networks.

While the group's specific targets were not detailed in the available reporting, state-sponsored actors like Nimbus Manticore typically pursue espionage objectives against government, defence, and business targets—including supply chain partners of larger organisations. Australian small businesses connected to larger enterprises, government contracts, or international supply chains should be aware that they can be used as a stepping stone into bigger targets.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.