THREATOPS
THREAT OPSThreat News › Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

lowthehackernewsPublished 2026-08-26

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).

Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka

Original source: https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html