Iranian State-Backed Hackers Add New Backdoor and Tunneling Tool to Arsenal
Cybersecurity researchers at Group-IB have identified new malware tools and infrastructure tied to Nimbus Manticore, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps (IRGC). The group has been named one of the most active Iranian advanced persistent threat (APT) actors observed in 2026.
According to the analysis, Nimbus Manticore has expanded its toolkit with a previously undocumented backdoor resembling a known malware family called TWOSTROKE, along with a tool designed to tunnel traffic over SSH connections. These additions suggest the group is continuing to invest in new capabilities for covert access and data exfiltration from compromised networks.
While the group's specific targets were not detailed in the available reporting, state-sponsored actors like Nimbus Manticore typically pursue espionage objectives against government, defence, and business targets—including supply chain partners of larger organisations. Australian small businesses connected to larger enterprises, government contracts, or international supply chains should be aware that they can be used as a stepping stone into bigger targets.