Find notable cyber news and cases, enriched with sources, timelines, and signals.

Tortoiseshell malware toolset adds reverse SSH tunnel and C++ backdoor

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The Tortoiseshell espionage group has expanded its malware toolset with a reverse SSH tunneling utility and a C++ backdoor, increasing the risk of covert access into compromised Windows networks. The new tooling is designed to disguise itself as `wtsapi32.dll`, redirect traffic through a compromised host, and support execution and transfer functions inside victim environments. Newly identified infrastructure linked to locat[.]sbs and tiktok-u[.]sbs suggests possible targeting across Europe and the Middle East.

Related Happenings

Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia

Campaign
H score32 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

About this happening: Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...

NightLedger, BridgeHead, and ArcBridge covert-access deployment

Malware Activity
H score23 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

About this happening: The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim syst...

GoSerpent malware activity targeting Southeast Asian entities

Malware Activity
H score26 First: 17.07.2026 11:46 Last: 17.07.2026 11:46 Sources 1

About this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

Showboat Linux post-exploitation backdoor framework

Malware Activity
H score16 First: 21.05.2026 17:17 Last: 21.05.2026 17:17 Sources 1

About this happening: The Showboat Linux malware has been identified as a modular post-exploitation framework used since at least mid-2022, raising the risk of persistent access on compromi...

Timeline

  1. 26.08.2026 17:30 2 articles · 2h ago

    Tortoiseshell adds a reverse SSH tunnel and C++ backdoor disguised as wtsapi32.dll

    Technical Analysis Update

    Group-IB identified a reverse SSH tunneling utility disguised as `wtsapi32.dll` and a separate C++ backdoor tied to Tortoiseshell (Mirage Kitten). The tunneling tool used Windows' OpenSSH client and forward-exported legitimate DLL functions while redirecting traffic from a command-and-control server into a compromised network. The backdoor, also disguised as `wtsapi32.dll`, appeared intended for DLL search-order hijacking, established HTTPS sessions to multiple hardcoded C2 servers, generated a unique identifier from the victim's fully qualified hostname, and supported file and shell command execution, in-memory DLL execution, file transfer, directory listing, and file deletion. Group-IB also linked locat[.]sbs and tiktok-u[.]sbs infrastructure to a previously known Tortoiseshell C2 domain and said the pattern may indicate targeting in Europe and the Middle East, while noting the group has operated since at least 2018 and has primarily targeted defense, aerospace, IT service providers, and military organizations.

    Show sources