Iran's Nimbus Manticore Adds New Backdoor and SSH Tunneler to Spy Kit

Group-IB says the IRGC-linked hackers have quietly built out fresh infrastructure and custom malware for espionage campaigns in 2026.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial image, 16:9, full-frame edge-to-edge
Share

Key points

  • Group-IB published new research on 2026 activity by Nimbus Manticore, an Iranian state-backed hacking crew tied to the Islamic Revolutionary Guard Corps.
  • The group has added a fresh backdoor resembling a tool called TWOSTROKE and a custom SSH tunneler to its espionage kit.
  • Analysts rank Nimbus Manticore among the most active Iranian state hacking groups so far this year.
  • Targets fit the familiar Iranian espionage pattern: defence, aerospace, telecoms, and diplomatic contacts across Europe and the Middle East.
  • The findings expand what defenders know about the group's servers and file names, giving security teams new things to block.

An Iranian government hacking crew has quietly upgraded its spying toolkit, and researchers now have a clearer picture of what to watch for.

The group is called Nimbus Manticore. Security company Group-IB, which tracks state-sponsored hackers, ties it to Iran's Islamic Revolutionary Guard Corps, the powerful military and intelligence body known as the IRGC. In a report published this week, Group-IB calls Nimbus Manticore one of the busiest Iranian hacking teams of 2026.

The headline finding: new infrastructure, meaning the servers and web domains the hackers use to run their operations, plus two pieces of malware that had not been publicly documented before.

Who are Nimbus Manticore?

They are a cyber espionage group, meaning their job is stealing secrets, not stealing money. Other researchers have tracked the same crew under different names over the years. Their usual targets sit in defence, aerospace, telecoms and government, mostly across Europe and the Middle East. Think of them as intelligence officers who work by keyboard instead of by dead-drop.

Iranian state hacking is nothing new. What matters here is that the group keeps refreshing its tools, which makes older detection rules go stale.

What's new in the toolkit?

Two things stand out. The first is a backdoor, a hidden program that gives attackers remote control of an infected computer, that behaves like a known piece of malware called TWOSTROKE. The second is a custom SSH tunneler.

SSH is a normal, legitimate way for IT staff to log into servers securely. A tunneler abuses that same channel to smuggle stolen data or attacker traffic through networks without setting off alarms. In plain terms, the hackers are hiding their comings and goings inside a protocol every network already trusts.

This is a very old trick with a fresh coat of paint. Web attackers have been tunnelling malicious traffic through trusted channels for two decades. What's notable is that a state group is bothering to write a bespoke version rather than grab an off-the-shelf tool. That usually means they want something quieter, and harder to attribute.

Should ordinary people worry?

Not directly. Nimbus Manticore is not chasing your bank details or your Netflix password. Their interest is in engineers, diplomats, defence contractors and the executives around them.

The practical risk to regular readers is second-hand. If your employer builds aircraft parts, sells telecoms gear, or advises a foreign ministry, you are more likely to receive a well-crafted phishing email, a fake message designed to trick you into opening a document or entering a password. Slow down on unexpected LinkedIn approaches and job offers, which this cluster of Iranian groups has used repeatedly.

What defenders should do now

Group-IB's report gives security teams fresh indicators of compromise, the technical fingerprints (file names, server addresses, behaviours) that let defenders spot an intrusion. Feed them into your detection tools. Watch outbound SSH traffic to unusual destinations. Treat unsolicited recruiter contact with a healthy dose of suspicion.

This is not a doomsday story. It is a reminder that a well-funded state crew keeps iterating, and that yesterday's block list is not today's.

© 2026 Threat Vectr