Tortoiseshell malware toolset adds reverse SSH tunnel and C++ backdoor
Malware Activity
Summary
Hide ▲
Show ▼
Group-IB reported that Nimbus Manticore/Tortoiseshell has added previously undocumented malware and new infrastructure spanning Europe and the Middle East. The tooling includes a reverse SSH tunneling utility disguised as wtsapi32.dll and a TWOSTROKE-like C++ backdoor that uses hard-coded C2 servers, including 172.86.98[.]113:443, for file transfer, host information collection, and remote execution. Group-IB said the infrastructure and tooling expansion suggests the activity is steadily evolving to maintain access across a growing number of targets.
Related Happenings
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
Campaign
H score32
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
How related:
The findings build upon a recent report from Kaspersky, which detailed the threat actor's use of a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain persistent access to compromised hosts in attacks aimed at entities across the Middle East, Africa, and South Asia.
About this happening:
Nimbus Manticore is running a covert-access campaign across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve access insi...
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
CampaignHow related: The findings build upon a recent report from Kaspersky, which detailed the threat actor's use of a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain persistent access to compromised hosts in attacks aimed at entities across the Middle East, Africa, and South Asia.
About this happening: Nimbus Manticore is running a covert-access campaign across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve access insi...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware Activity
H score23
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
How related:
The findings build upon a recent report from Kaspersky, which detailed the threat actor's use of a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain persistent access to compromised hosts in attacks aimed at entities across the Middle East, Africa, and South Asia.
About this happening:
Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware ActivityHow related: The findings build upon a recent report from Kaspersky, which detailed the threat actor's use of a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain persistent access to compromised hosts in attacks aimed at entities across the Middle East, Africa, and South Asia.
About this happening: Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...
Latest development: 26.08.2026 18:35
Group-IB found additional Tortoiseshell infrastructure spanning Europe and the Middle East, including a reverse SSH tunneling tool that masquerades as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 on port 443, plus a C++ backdoor that mimics wtsapi32.dll and uses hard-coded C2 servers to download and upload files, execute binaries or DLLs, gather host information, list directories, and delete files.
GoSerpent malware activity targeting Southeast Asian entities
Malware Activity
H score26
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GoSerpent malware activity targeting Southeast Asian entities
Malware ActivityAbout this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Showboat Linux post-exploitation backdoor framework
Malware Activity
H score16
First: 21.05.2026 17:17
Last: 21.05.2026 17:17
Sources 1
About this happening:
The Showboat Linux malware has been identified as a modular post-exploitation framework used since at least mid-2022, raising the risk of persistent access on compromi...
Showboat Linux post-exploitation backdoor framework
Malware ActivityAbout this happening: The Showboat Linux malware has been identified as a modular post-exploitation framework used since at least mid-2022, raising the risk of persistent access on compromi...
Timeline
-
26.08.2026 17:30 3 articles · 13d ago
Tortoiseshell adds a reverse SSH tunnel and C++ backdoor disguised as wtsapi32.dll
Technical Analysis UpdateGroup-IB identified a reverse SSH tunneling utility disguised as `wtsapi32.dll` and a separate C++ backdoor tied to Tortoiseshell (Mirage Kitten). The tunneling tool used Windows' OpenSSH client and forward-exported legitimate DLL functions while redirecting traffic from a command-and-control server into a compromised network. The backdoor, also disguised as `wtsapi32.dll`, appeared intended for DLL search-order hijacking, established HTTPS sessions to multiple hardcoded C2 servers, generated a unique identifier from the victim's fully qualified hostname, and supported file and shell command execution, in-memory DLL execution, file transfer, directory listing, and file deletion. Group-IB also linked locat[.]sbs and tiktok-u[.]sbs infrastructure to a previously known Tortoiseshell C2 domain and said the pattern may indicate targeting in Europe and the Middle East, while noting the group has operated since at least 2018 and has primarily targeted defense, aerospace, IT service providers, and military organizations.
Show sources
- Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel — www.infosecurity-magazine.com — 26.08.2026 17:30
- Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel — www.infosecurity-magazine.com — 26.08.2026 17:30
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler — thehackernews.com — 26.08.2026 18:35