In the ever-escalating landscape of cyber warfare, a prominent Iranian state-sponsored hacking group, Nimbus Manticore, has once again drawn the attention of cybersecurity researchers. Affiliated with the Islamic Revolutionary Guard Corps (IRGC), this sophisticated threat actor is demonstrating a significant expansion of its operational capabilities, incorporating new malware and infrastructure that underscore its persistent and evolving threat.
Nimbus Manticore: A Persistent Threat on the Global Stage
Cybersecurity firm Group-IB, in a recent analysis, has identified Nimbus Manticore (also known by aliases such as GalaxyGato, Mirage Kitten, and Smoke Sandstorm) as one of the most active Iranian Advanced Persistent Threat (APT) groups. The group’s activities are closely linked to Tortoiseshell (aka Imperial Kitten), which itself is part of the broader Charming Kitten cluster. Tortoiseshell has a documented history of operations dating back to at least July 2018, primarily focusing on critical sectors like defense, aerospace, IT service providers, and military organizations across the Middle East and the United States.
Nimbus Manticore is notorious for its cunning social engineering tactics, including its own variant of the “Dream Job” campaign. This involves luring targets with fake job opportunities to deploy malware, a testament to their sophisticated approach to initial access.
Unveiling New Infrastructure and Advanced Tooling
Expanded Targeting Profile
Group-IB’s latest findings reveal an extensive Tortoiseshell infrastructure stretching across Europe and the Middle East. This discovery suggests a potential broadening of Nimbus Manticore’s targeting scope beyond its traditional Middle Eastern and U.S. focus, now actively including European countries. This geographical expansion signifies a growing ambition and reach for the Iranian threat actor.
The TWOSTROKE-Like Backdoor and SSH Tunneler
Central to the new discoveries are two critical pieces of malware: an SSH-based tunneling utility and a C++ backdoor. The backdoor exhibits striking similarities to TWOSTROKE, an implant already attributed to Nimbus Manticore. This C++ implant is designed for comprehensive system information collection, dynamic DLL loading, file manipulation, and maintaining persistence on compromised systems.
Mimicking the Windows Terminal Server SDK DLL (“wtsapi32.dll”), the backdoor establishes secure HTTPS connections to one of three hard-coded command-and-control (C2) servers. Upon receiving instructions, it spawns a new worker thread to execute commands, enabling a wide array of malicious activities, including:
- Downloading and uploading files
- Executing binaries or DLLs
- Gathering detailed host information
- Listing directory contents
- Deleting specific files
The newly identified reverse SSH tunneling tool further enhances the group’s stealth and persistence. It cleverly masquerades as the Windows Terminal Server SDK API while establishing an SSH connection to the operator’s infrastructure (specifically “172.86.98[.]113” on port 443), providing a covert channel for data exfiltration and remote control.
Building on Previous Intelligence
These revelations complement a recent report from Kaspersky, which detailed Nimbus Manticore’s use of a new Windows backdoor named NightLedger, alongside custom WebSocket tunnelers, BridgeHead and ArcBridge. These tools were employed to maintain persistent access to compromised hosts in attacks targeting entities across the Middle East, Africa, and South Asia.
A Steadily Evolving Threat
The consistent development of new tools, such as the TWOSTROKE-like backdoor and advanced SSH tunneling utilities, coupled with an expanding infrastructure, paints a clear picture: Nimbus Manticore is a threat actor that is continuously refining its arsenal and adapting its techniques. This evolution allows them to maintain access across an increasing number of targets, posing a significant and ongoing challenge to global cybersecurity efforts.
Stay informed on the latest cybersecurity threats. Follow us on Google News, Twitter, and LinkedIn for exclusive insights and updates.
For more details, visit our website.
Source: Link


Leave a comment