Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool

Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool

First seen 26 Aug 2026, 14:53 UTC Group-IbGbhackerssecurelist.comCybersecuritynewsInfosecurity-Magazine+1 77.0

Article Content

Browse articles
ThreatCluster

The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by Kaspersky. The group, also known as Mirage Kitten, has been active since at least 2018, primarily targeting defense and aerospace sectors in the Middle East and the US. The new backdoor, similar to the previously documented TWOSTROKE malware, is disguised as the Windows Terminal Server API DLL. It supports various malicious functions, including file manipulation and command execution. The reverse SSH tunneling tool enables covert access to compromised networks by redirecting traffic from command-and-control servers. Group-IB's findings suggest a broader targeting scope across Europe and the Middle East. The group has been linked to operations supporting Iran's Islamic Revolutionary Guard Corps (IRGC). Current intelligence indicates ongoing activity and potential threats to various sectors.

Key Points: • Tortoiseshell has introduced a new backdoor and reverse SSH tunneling tool. • The group targets defense and aerospace sectors, expanding its operations into Europe. • The new malware is designed for covert access and supports various malicious functions.

Timeline

2026-08-26
Group-IB publishes findings on Tortoiseshell
Group-IB identified new malware samples and infrastructure linked to Tortoiseshell, revealing expanded capabilities.
Group-IB
2026-08-26
Kaspersky reports on Tortoiseshell activity
Kaspersky's report on Tortoiseshell prompted further investigation by Group-IB, leading to new discoveries.
Securelist
2026-08-26
Tortoiseshell linked to IRGC
The group is associated with Iran's Islamic Revolutionary Guard Corps and has been active since at least 2018.
Infosecurity-Magazine