Tortoiseshell malware toolset adds reverse SSH tunnel and C++ backdoor
Malware Activity
Summary
Hide ▲
Show ▼
The Tortoiseshell espionage group has expanded its malware toolset with a reverse SSH tunneling utility and a C++ backdoor, increasing the risk of covert access into compromised Windows networks. The new tooling is designed to disguise itself as `wtsapi32.dll`, redirect traffic through a compromised host, and support execution and transfer functions inside victim environments. Newly identified infrastructure linked to locat[.]sbs and tiktok-u[.]sbs suggests possible targeting across Europe and the Middle East.
Related Happenings
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
Campaign
H score32
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
CampaignAbout this happening: Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware Activity
H score23
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim syst...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware ActivityAbout this happening: The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim syst...
GoSerpent malware activity targeting Southeast Asian entities
Malware Activity
H score26
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GoSerpent malware activity targeting Southeast Asian entities
Malware ActivityAbout this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Showboat Linux post-exploitation backdoor framework
Malware Activity
H score16
First: 21.05.2026 17:17
Last: 21.05.2026 17:17
Sources 1
About this happening:
The Showboat Linux malware has been identified as a modular post-exploitation framework used since at least mid-2022, raising the risk of persistent access on compromi...
Showboat Linux post-exploitation backdoor framework
Malware ActivityAbout this happening: The Showboat Linux malware has been identified as a modular post-exploitation framework used since at least mid-2022, raising the risk of persistent access on compromi...
Timeline
-
26.08.2026 17:30 2 articles · 2h ago
Tortoiseshell adds a reverse SSH tunnel and C++ backdoor disguised as wtsapi32.dll
Technical Analysis UpdateGroup-IB identified a reverse SSH tunneling utility disguised as `wtsapi32.dll` and a separate C++ backdoor tied to Tortoiseshell (Mirage Kitten). The tunneling tool used Windows' OpenSSH client and forward-exported legitimate DLL functions while redirecting traffic from a command-and-control server into a compromised network. The backdoor, also disguised as `wtsapi32.dll`, appeared intended for DLL search-order hijacking, established HTTPS sessions to multiple hardcoded C2 servers, generated a unique identifier from the victim's fully qualified hostname, and supported file and shell command execution, in-memory DLL execution, file transfer, directory listing, and file deletion. Group-IB also linked locat[.]sbs and tiktok-u[.]sbs infrastructure to a previously known Tortoiseshell C2 domain and said the pattern may indicate targeting in Europe and the Middle East, while noting the group has operated since at least 2018 and has primarily targeted defense, aerospace, IT service providers, and military organizations.
Show sources
- Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel — www.infosecurity-magazine.com — 26.08.2026 17:30
- Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel — www.infosecurity-magazine.com — 26.08.2026 17:30