Nation-StateThe Hacker News·3 hours ago
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Researchers at Group-IB have identified new infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored group affiliated with the IRGC, including a TWOSTROKE-like backdoor and SSH tunneler. The analysis ranks Nimbus Manticore among the most active Iranian APT groups operating in 2026.