Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Summary

Cybersecurity researchers have uncovered new malware and infrastructure linked to Nimbus Manticore, an Iranian state-sponsored hacking group associated with the IRGC. The group is noted for its significant activity in espionage operations.

IFF Assessment

FOE

The discovery of new tools and infrastructure used by a state-sponsored hacking group poses an increased threat to defenders.

Defender Context

The continued development and deployment of advanced tools by state-sponsored groups like Nimbus Manticore highlight the persistent threat of sophisticated cyber espionage. Defenders should remain vigilant for the indicators of compromise associated with this group and similar Iranian APTs, particularly focusing on network traffic patterns and novel malware signatures.

Read Full Story →