Infosecurity-Magazine
Tortoiseshell APT Expands Malware Capabilities with New Tools
Article Content
The Tortoiseshell APT group, linked to Iran, has expanded its malware toolkit with a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these tools following Kaspersky's report on the group's activities. The new backdoor, similar to the previously reported TWOSTROKE malware, masquerades as the Windows Terminal Server API DLL (wtsapi32.dll) and is designed for DLL-order hijacking. The reverse SSH tunneling utility allows attackers to redirect traffic from compromised networks back to their command-and-control infrastructure. The group's targeting scope now appears to extend beyond the Middle East to include Europe, with infrastructure linked to multiple countries. Group-IB has recommended ongoing threat hunting and monitoring for unusual activity related to Tortoiseshell's tools. The group has been active since at least 2018, primarily targeting defense and military sectors. The current status indicates heightened activity from Tortoiseshell in 2026.
Key Points: • Tortoiseshell APT has expanded its malware toolkit with new backdoor and tunneling tools. • The new backdoor is designed for DLL hijacking and supports various malicious functions. • Tortoiseshell's targeting scope now includes Europe, indicating a broader operational reach.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.