highAPT

Nimbus Manticore Backdoor and SSH Tunneler Campaign

First seen Aug 27, 2026 · Updated Aug 27, 2026

IranIRGCnation-stateespionagebackdoorSSH-tunnelingNimbus ManticoreAPT

Nimbus Manticore, an Iranian state-sponsored APT group affiliated with the IRGC, has expanded its toolset with a new TWOSTROKE-like backdoor and an SSH tunneling utility, according to Group-IB research. The group is characterized as one of the most active Iranian threat actors in 2026, conducting cyber espionage operations using newly discovered infrastructure and malware.

Technical Analysis

The threat actor has deployed a previously undocumented backdoor resembling the known TWOSTROKE family, paired with an SSH tunneling tool likely used for covert command-and-control communications and lateral movement within compromised networks. The use of SSH tunneling suggests an emphasis on evading network-based detection by encapsulating malicious traffic within legitimate-looking encrypted channels. Full technical details on initial access vectors, encryption schemes, and specific IOCs were not disclosed in available reporting, though the campaign aligns with established IRGC-affiliated espionage tradecraft targeting government, defense, and critical infrastructure sectors. If compromised hosts include servers running AI agent orchestration, RAG pipelines, or LLM tool-use frameworks, the backdoor and tunneling capability could enable exfiltration of API keys, model credentials, and sensitive agent-accessible data, warranting explicit review of agent-hosting infrastructure for exposure.

Affected Systems

Enterprise networks and servers targeted by Nimbus Manticore; specific OS/software versions not disclosed in available reporting

Indicators of Compromise

  • Specific hashes, IPs, and domains not disclosed in the source reporting; refer to Group-IB's full analysis for detailed IOCs

Remediation Steps

  1. 1

    Monitor SSH Traffic Anomalies

    Inspect outbound SSH connections for unusual tunneling patterns, unexpected destinations, or non-standard ports indicative of covert C2 channels.

  2. 2

    Threat Intelligence Integration

    Ingest Group-IB's published IOCs and YARA/Sigma rules once available into SIEM and EDR platforms for detection of TWOSTROKE-like backdoor artifacts.

  3. 3

    Review Credential and API Key Exposure

    Audit systems hosting AI agents, LLM APIs, and RAG pipelines for signs of compromise, and rotate any credentials or API keys potentially exposed.

  4. 4

    Network Segmentation

    Restrict lateral movement opportunities by segmenting critical infrastructure and agent-hosting environments from general enterprise networks.

  5. 5

    Enhanced Endpoint Detection

    Deploy behavioral detection for backdoor persistence mechanisms and unauthorized SSH tunnel creation on endpoints and servers.

Industries Most Exposed

GovernmentDefenseCritical InfrastructureTelecommunicationsTechnology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.