< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-26T21:05:05+05:30

Iranian APT Group Nimbus Manticore Enhances Cyber Espionage Capabilities with Advanced Backdoor and SSH Tunneling Tools

Cybersecurity firm Group-IB identified new malware tools linked to Iranian APT group Nimbus Manticore, including a TWOSTROKE-like backdoor and SSH tunneling utility, expanding their cyber espionage capabilities. The threat actor is targeting Middle Eastern and European entities with advanced persistence techniques and infrastructure development.

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).

Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka

Read original article

*** END OF TRANSMISSION ***