Iran's Nimbus Manticore Adds New Backdoor and SSH Tunneler to Spy Kit

Group-IB says the IRGC-linked hackers have quietly built out fresh infrastructure and custom malware for espionage campaigns in 2026.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A computer terminal displaying encrypted command-line output and network packet traces, with shadowy server rack infrastructure visible in the background sugges
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Group-IB published new research on 2026 activity by Nimbus Manticore, an Iranian state-backed hacking crew tied to the Islamic Revolutionary Guard Corps.
  • The group has added a fresh backdoor resembling a tool called TWOSTROKE and a custom SSH tunneler to its espionage kit.
  • Analysts rank Nimbus Manticore among the most active Iranian state hacking groups so far this year.
  • Targets fit the familiar Iranian espionage pattern: defence, aerospace, telecoms and diplomatic contacts across Europe and the Middle East.
  • The findings expand what defenders know about the group's servers and file names, giving security teams new things to block.

An Iranian government hacking crew has quietly upgraded its spying toolkit, and researchers now have a clearer picture of what to watch for.

The group is called Nimbus Manticore. Security company Group-IB ties it to Iran's IRGC, the country's powerful military-intelligence body. In a report published this week, Group-IB calls Nimbus Manticore one of the busiest Iranian hacking teams of 2026. We first reported on the group back in May, and our July story on the NightLedger backdoor campaign found it was already turning victim machines into relay points.

The headline finding this time: fresh infrastructure, meaning the servers and domains the hackers use to run operations, plus two pieces of malware that had not been publicly documented before.

Who are Nimbus Manticore?

They are a cyber espionage group, meaning their job is stealing secrets rather than stealing money. Other researchers have tracked the same crew under different names. Their usual targets sit in defence, aerospace and telecoms, mostly across Europe and the Middle East. Think of them as intelligence officers who work by keyboard rather than dead-drop.

What matters here is that the group keeps refreshing its tools, which makes older detection rules go stale.

What's new in the toolkit?

Two things stand out. A new backdoor, a hidden program that gives attackers remote control of an infected computer, behaves like a known piece of malware called TWOSTROKE. On top of that, there's a custom SSH tunneler.

SSH is a legitimate way for IT staff to log into servers securely. A tunneler abuses that same channel to smuggle stolen data or attacker traffic through networks without setting off alarms. In plain terms, the hackers are hiding their comings and goings inside a protocol every network already trusts.

This is an old trick with a fresh coat of paint. Web attackers have been tunnelling malicious traffic through trusted channels for two decades. What's notable is that a state group is bothering to write a bespoke version rather than grab an off-the-shelf tool. That usually means they want something quieter and harder to attribute.

Should ordinary people worry?

Not directly. Nimbus Manticore is not chasing your bank details or your Netflix password. Their interest is in engineers, diplomats, defence contractors and the executives around them.

The practical risk to regular readers is second-hand. If your employer operates in aerospace, telecoms or foreign-policy consulting, you're more likely to receive a well-crafted phishing email, a fake message designed to trick you into opening a document or entering a password. Slow down on unexpected LinkedIn approaches and job offers, which this cluster of Iranian groups has used repeatedly.

What defenders should do now

Group-IB's report gives security teams fresh indicators of compromise, the technical fingerprints (file names, server addresses, behaviours) that let defenders spot an intrusion. Feed them into your detection tools. Watch outbound SSH traffic to unusual destinations. Given our August story on federal charges against 17 Iranians who stole more than 31 terabytes on the IRGC's behalf, the legal pressure on these actors is real, yet the tooling keeps getting more refined.

This is not a doomsday story. It is a reminder that a well-funded state crew keeps iterating, and that yesterday's block list is not today's.

© 2026 Threat Vectr