Iranian state-sponsored threat group Nimbus Manticore has expanded its operational toolkit with a custom SSH tunneling utility and an evolved variant of its TWOSTROKE backdoor, according to a new analysis by Group-IB. The findings, reported by The Hacker News, detail a strategic pivot toward stealth and long-term persistence by the actor, which threat intelligence researchers identify as affiliated with the Islamic Revolutionary Guard Corps (IRGC). In response to these tactics, Group-IB advises security teams to transition from signature-based monitoring to behavior-driven analytics and enforce strict zero-trust controls over administrative access.
Group-IB characterizes Nimbus Manticore as one of the most active Iranian-aligned advanced persistent threat groups operating in 2026. Rather than deploying disruptive payloads, the group’s updated toolchain prioritizes operational security by encapsulating command-and-control traffic within standard Secure Shell sessions. According to the report, this protocol abuse allows operators to blend malicious activity into legitimate administrative traffic, effectively bypassing perimeter defenses that lack deep packet inspection or behavioral monitoring. The newly documented SSH tunneler operates alongside the refined TWOSTROKE backdoor to establish a resilient, low-profile foothold for sustained espionage.
To counter these methods, the report recommends that defenders reduce reliance on static indicators of compromise (IOCs) and adopt continuous behavioral analytics. Group-IB outlines specific mitigation steps, including the implementation of certificate-based SSH authentication, the complete disabling of password-based logins, and strict egress filtering on privileged subnets to disrupt covert command channels. The analysis further advises security operations centers to prioritize endpoint telemetry and process-level monitoring to detect anomalous SSH session patterns, unexpected outbound connections, and code injection techniques that typically precede lateral movement.
To support rapid detection, Group-IB has published a comprehensive set of network signatures and IOCs, urging organizations to integrate them into existing security information and event management (SIEM) and endpoint detection and response (EDR) pipelines. The report emphasizes that open telemetry sharing and community-driven threat feeds serve as critical enablers against protocol-abusing campaigns. As state-sponsored actors increasingly leverage trusted administrative tools, the analysis concludes that sustained visibility into privileged traffic and proactive zero-trust segmentation are essential for identifying and disrupting covert infrastructure before it escalates.
根據 Group-IB 的最新分析,伊朗國家背景威脅組織 Nimbus Manticore 已擴展其行動工具包,加入自訂的 SSH 隧道工具及其 TWOSTROKE 後門的進化版本。《The Hacker News》的報導詳細說明,該攻擊者(威脅情報研究人員指其與伊斯蘭革命衛隊 IRGC 有關聯)正進行策略性轉向,專注於隱蔽行動與長期潛伏。針對上述手法,Group-IB 建議安全團隊由基於特徵碼的監控轉向行為驅動分析,並對管理存取實施嚴格的 zero-trust 控制。
Group-IB 將 Nimbus Manticore 列為 2026 年最活躍的伊朗陣營 APT 組織之一。該組織更新後的工具鏈不再部署具破壞性的 payload,而是將 command-and-control 流量封裝於標準的 Secure Shell 會話中,以優先保障 operational security。報告指出,此類協議濫用手法使操作員得以將惡意活動混入合法的管理流量,有效繞過缺乏深度封包檢查或行為監控的網絡邊界防禦。新披露的 SSH 隧道工具與改良版 TWOSTROKE 後門協同運作,為持續間諜活動建立具韌性且低調的立足點。
為應對上述手法,報告建議防禦者減少對靜態入侵指標(IOC)的依賴,並採用持續性行為分析。Group-IB 列出具體的緩解措施,包括實施基於數碼憑證的 SSH 認證、完全停用密碼登入,以及在特權子網實施嚴格的出口過濾,以切斷隱蔽的命令通道。分析進一步建議安全營運中心優先關注端點遙測數據及程序層級監控,以偵測異常的 SSH 會話模式、意外的對外連線,以及通常在橫向移動前出現的 code injection 技術。
為支援快速偵測,Group-IB 已發布一套完整的網絡特徵碼與 IOC,敦促各機構將其整合至現有的 SIEM 與 EDR pipeline。報告強調,開放式遙測數據共享與社群驅動的威脅情報源,是應對協議濫用攻擊活動的關鍵助力。分析總結指出,隨著國家背景攻擊者日益利用受信任的管理工具,對特權流量的持續可視性及主動的 zero-trust 網絡分段,已成為在隱蔽基礎設施升級前識別並中斷其運作的必要條件。
