LONDON — Cybersecurity researchers have identified new infrastructure and malware associated with the Iran-linked threat group Tortoiseshell, indicating that the group is broadening its operational footprint across Europe and the Middle East while continuing to develop tools for espionage and long-term network access.
Group-IB tracks Tortoiseshell under several names, including Mirage Kitten, UNC1549, and Nimbus Manticore, and describes the group as an Iranian-nexus advanced persistent threat actor affiliated with the Islamic Revolutionary Guard Corps. The group has been active since at least 2018 and has historically targeted defense, aerospace, military, and information-technology organizations.
The latest research identified infrastructure spanning Europe and the Middle East, with Group-IB assessing that the activity potentially points to an expanded targeting profile across both regions.
Group-IB found country-themed subdomains including uk1, uk2, multiple uae identifiers, and sau identifiers tied to infrastructure associated with the group.
Researchers cautioned that the naming alone does not prove which countries or organizations were targeted. The operational purpose of some of the infrastructure remains unclear, and no related malware samples were identified for every server discovered.
The investigation also uncovered a reverse SSH tunneling utility disguised as a Windows Terminal Server API file named wtsapi32.dll.
According to Group-IB, the tool establishes an outbound encrypted SSH connection from a compromised system to attacker-controlled infrastructure. Traffic from the command-and-control server can then be routed back through that tunnel into the victim’s network.
This technique can allow attackers to maintain access to internal systems while avoiding defenses designed primarily to block unsolicited inbound connections.
Researchers also identified a newly observed backdoor closely resembling TWOSTROKE, a C++ malware family previously documented by Google Threat Intelligence Group in connection with UNC1549.
TWOSTROKE provides capabilities including system reconnaissance, command execution, file manipulation, and uploading and exfiltration of data. Google has also documented the malware’s use as part of UNC1549’s broader persistence operations.
Google previously documented UNC1549 using TWOSTROKE and other custom malware during operations targeting aerospace, aviation, and defense organizations. Google also observed the group using DLL search-order hijacking, credential theft, spear-phishing, and trusted third-party relationships to gain and maintain access.
Group-IB’s analysis found that the newly identified TWOSTROKE-like sample uses multiple hardcoded command-and-control servers and communicates with them through HTTPS.
The malware creates a unique identifier for each infected system using the machine’s fully qualified hostname before establishing communication with attacker infrastructure.
The use of multiple command-and-control servers gives the operators additional resilience if one server becomes unavailable.
Group-IB also identified infrastructure associated with domains including locat[.]sbs and tiktok-u[.]sbs, along with a larger set of related subdomains and IP addresses spread across several hosting providers and geographic regions.
Tortoiseshell has previously relied on a mixture of phishing, fake recruitment websites, supply-chain compromise, watering-hole activity, and custom backdoors.
Google assessed with moderate confidence that UNC1549 overlaps with Tortoiseshell and described the activity as Iran-based espionage targeting aerospace and defense organizations in the Middle East, including Israel and the United Arab Emirates, with possible activity involving Turkey, India, and Albania.
The latest infrastructure findings suggest the group is continuing to develop operations beyond its earlier geographic concentration.
Group-IB said the newly identified servers potentially point to expanded targeting across both European and Middle Eastern countries, while the malware findings show continued investment in tools capable of maintaining covert access and moving traffic through compromised networks.
The research does not establish that every country-themed server was used against a victim in the country reflected by its name.
It also does not identify specific organizations compromised through the newly discovered infrastructure.
For defenders, the combination of reverse SSH tunneling, custom backdoors, multiple command-and-control servers, and geographically distributed infrastructure presents a persistent threat to organizations operating in defense, aerospace, government-adjacent, and technology environments.
Group-IB recommends persistent threat hunting, monitoring for known Tortoiseshell indicators, deploying endpoint detection capabilities, and examining outbound traffic for command-and-control behavior associated with the group.
The latest findings reinforce Tortoiseshell’s position as an active Iranian-linked espionage group capable of adapting its infrastructure and tooling while maintaining a focus on high-value strategic targets.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



