Find notable cyber news and cases, enriched with sources, timelines, and signals.

Tortoiseshell malware toolset adds reverse SSH tunnel and C++ backdoor

Malware Activity
First reported
Last updated
Happening score
H score 23
2 unique sources, 2 articles

Summary

Hide ▲

Group-IB reported that Nimbus Manticore/Tortoiseshell has added previously undocumented malware and new infrastructure spanning Europe and the Middle East. The tooling includes a reverse SSH tunneling utility disguised as wtsapi32.dll and a TWOSTROKE-like C++ backdoor that uses hard-coded C2 servers, including 172.86.98[.]113:443, for file transfer, host information collection, and remote execution. Group-IB said the infrastructure and tooling expansion suggests the activity is steadily evolving to maintain access across a growing number of targets.

Related Happenings

Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia

Campaign
H score32 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

How related: The findings build upon a recent report from Kaspersky, which detailed the threat actor's use of a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain persistent access to compromised hosts in attacks aimed at entities across the Middle East, Africa, and South Asia.

About this happening: Nimbus Manticore is running a covert-access campaign across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve access insi...

NightLedger, BridgeHead, and ArcBridge covert-access deployment

Malware Activity
H score23 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

How related: The findings build upon a recent report from Kaspersky, which detailed the threat actor's use of a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain persistent access to compromised hosts in attacks aimed at entities across the Middle East, Africa, and South Asia.

About this happening: Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...

Latest development: 26.08.2026 18:35

Group-IB found additional Tortoiseshell infrastructure spanning Europe and the Middle East, including a reverse SSH tunneling tool that masquerades as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 on port 443, plus a C++ backdoor that mimics wtsapi32.dll and uses hard-coded C2 servers to download and upload files, execute binaries or DLLs, gather host information, list directories, and delete files.

GoSerpent malware activity targeting Southeast Asian entities

Malware Activity
H score26 First: 17.07.2026 11:46 Last: 17.07.2026 11:46 Sources 1

About this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

Showboat Linux post-exploitation backdoor framework

Malware Activity
H score16 First: 21.05.2026 17:17 Last: 21.05.2026 17:17 Sources 1

About this happening: The Showboat Linux malware has been identified as a modular post-exploitation framework used since at least mid-2022, raising the risk of persistent access on compromi...

Timeline

  1. 26.08.2026 17:30 3 articles · 13d ago

    Tortoiseshell adds a reverse SSH tunnel and C++ backdoor disguised as wtsapi32.dll

    Technical Analysis Update

    Group-IB identified a reverse SSH tunneling utility disguised as `wtsapi32.dll` and a separate C++ backdoor tied to Tortoiseshell (Mirage Kitten). The tunneling tool used Windows' OpenSSH client and forward-exported legitimate DLL functions while redirecting traffic from a command-and-control server into a compromised network. The backdoor, also disguised as `wtsapi32.dll`, appeared intended for DLL search-order hijacking, established HTTPS sessions to multiple hardcoded C2 servers, generated a unique identifier from the victim's fully qualified hostname, and supported file and shell command execution, in-memory DLL execution, file transfer, directory listing, and file deletion. Group-IB also linked locat[.]sbs and tiktok-u[.]sbs infrastructure to a previously known Tortoiseshell C2 domain and said the pattern may indicate targeting in Europe and the Middle East, while noting the group has operated since at least 2018 and has primarily targeted defense, aerospace, IT service providers, and military organizations.

    Show sources