
Iranian-Linked 'Nimbus Manticore' Expands Espionage Arsenal with Advanced Backdoors
Security researchers have identified a surge in activity from the Iranian state-sponsored group Nimbus Manticore. The group is deploying sophisticated new backdoors and SSH tunneling tools to maintain long-term persistence in targeted government and critical infrastructure networks.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Middle East
- Confidence:
- High Confidence
- Source:
- Group-IB
- Read Time:
- 4 min
Executive Summary
Recent intelligence analysis has uncovered a significant expansion in the operational capabilities of the Iranian-affiliated threat actor known as Nimbus Manticore. Linked to the Islamic Revolutionary Guard Corps (IRGC), this group has been identified as one of the most active cyber-espionage entities throughout 2026. Their latest campaign involves the deployment of a previously undocumented, TWOSTROKE-like backdoor and advanced SSH tunneling mechanisms designed to bypass traditional perimeter defenses.
Threat Analysis
Nimbus Manticore continues to demonstrate a strategic focus on long-term intelligence collection. By leveraging custom-built malware, the group maintains a low profile while exfiltrating sensitive diplomatic and government data. The shift toward modular backdoors suggests an evolution in their ability to adapt to specific target environments, allowing them to pivot quickly once initial access is established.
Technical Details
The newly discovered toolset includes a sophisticated backdoor that mirrors the functionality of the known TWOSTROKE malware. Key technical features include:
- Modular Architecture: The malware utilizes a plugin-based system to execute specific commands, minimizing the footprint of the primary payload.
- SSH Tunneling: The group is employing custom SSH tunneling tools to create encrypted, persistent communication channels, effectively masking command-and-control (C2) traffic as legitimate administrative activity.
- Persistence Mechanisms: The actors are utilizing advanced obfuscation techniques to hide their presence within system memory, complicating detection by standard endpoint security solutions.
Attribution Assessment
Based on infrastructure overlaps and tactical similarities, researchers have attributed this campaign to Nimbus Manticore. The group’s operational tempo and target selection—specifically entities of interest to the Iranian state—align with the known objectives of IRGC-affiliated cyber units. The use of custom-developed tools indicates a high level of resourcing and technical maturity.
Implications
The expansion of Nimbus Manticore’s toolkit poses a heightened risk to government agencies and critical infrastructure providers. The ability to maintain stealthy, long-term access through encrypted tunnels significantly increases the difficulty of incident response and remediation efforts. Organizations must prepare for prolonged exposure to these sophisticated espionage tactics.
Recommendations
- Enhanced Monitoring: Implement behavioral analytics to detect anomalous SSH traffic and unauthorized tunneling attempts within the network.
- Memory Scanning: Deploy advanced endpoint detection and response (EDR) tools capable of identifying fileless malware and memory-resident threats.
- Zero Trust Architecture: Enforce strict segmentation and identity-based access controls to limit the lateral movement capabilities of potential intruders.
- Threat Hunting: Conduct proactive threat hunting exercises focused on identifying indicators of compromise (IOCs) associated with the latest Nimbus Manticore infrastructure.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iranian 'Nimbus Manticore' APT Escalates Global Espionage via Sophisticated Coding Test Phishing

China-Linked Jewelbug Group Escalates Espionage and Crypto Fraud Across Middle East and Asia

