Tortoiseshell APT Expands Malware Capabilities with New Tools

Tortoiseshell APT Expands Malware Capabilities with New Tools

First seen 26 Aug 2026, 14:53 UTC Group-IbGbhackerssecurelist.comInfosecurity-Magazine 63.0

Article Content

Browse articles
ThreatCluster

The Tortoiseshell APT group, linked to Iran, has expanded its malware toolkit with a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these tools following Kaspersky's report on the group's activities. The new backdoor, similar to the previously reported TWOSTROKE malware, masquerades as the Windows Terminal Server API DLL (wtsapi32.dll) and is designed for DLL-order hijacking. The reverse SSH tunneling utility allows attackers to redirect traffic from compromised networks back to their command-and-control infrastructure. The group's targeting scope now appears to extend beyond the Middle East to include Europe, with infrastructure linked to multiple countries. Group-IB has recommended ongoing threat hunting and monitoring for unusual activity related to Tortoiseshell's tools. The group has been active since at least 2018, primarily targeting defense and military sectors. The current status indicates heightened activity from Tortoiseshell in 2026.

Key Points: • Tortoiseshell APT has expanded its malware toolkit with new backdoor and tunneling tools. • The new backdoor is designed for DLL hijacking and supports various malicious functions. • Tortoiseshell's targeting scope now includes Europe, indicating a broader operational reach.

Timeline

2026-08-26
Group-IB reports on Tortoiseshell's new tools
Group-IB identifies new malware samples and infrastructure linked to Tortoiseshell, expanding its operational capabilities.
Group-IB
2026-08-26
Infosecurity-Magazine covers Tortoiseshell's activities
Infosecurity-Magazine reports on Tortoiseshell's new backdoor and SSH tunneling utility, highlighting its espionage capabilities.
Infosecurity-Magazine
2026-08-26
Gbhackers reports on Tortoiseshell's espionage toolkit
Gbhackers discusses Tortoiseshell's expansion of its espionage toolkit, including reverse SSH tunneling utilities.
Gbhackers