Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Iran‑Linked APT ‘Tortoiseshell’ Expands Server Infrastructure Across Europe and Middle East, Raising Espionage Risks

Group‑IB uncovered new servers and malware linked to the Iranian‑backed APT group Tortoiseshell in the UK, Belgium, Saudi Arabia and the UAE. The discovery highlights the need for continuous monitoring and control mapping to meet SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
therecord.media

Iran‑Linked APT “Tortoiseshell” Expands Server Infrastructure Across Europe and the Middle East

What Happened — Researchers at Group‑IB identified new servers and domains tied to the Iranian‑linked threat actor Tortoiseshell in the United Kingdom, Belgium, Saudi Arabia and the United Arab Emirates. The group’s newly‑found malware includes a TwoStroke‑style backdoor and a reverse‑SSH tunneling tool that give attackers broad control over compromised hosts.

Why It Matters for Compliance & Audit Readiness

  • The expansion shows how nation‑state actors can silently add footholds, making continuous monitoring of network and third‑party assets a core SOC 2 control.
  • Reverse‑SSH tunnels bypass perimeter defenses, highlighting the need for documented logical‑access controls (CC6.1) and evidence‑ready monitoring.
  • Mapping these new vectors to your control framework provides audit‑ready proof that remote‑access and supply‑chain risks are being actively managed.

Who Is Affected — Defense, aerospace, technology and military organizations in the Middle East, United States and now Europe.

Recommended Actions

  • Update your asset inventory to include all external IPs and domains; map them to SOC 2 logical‑access and system‑monitoring controls.
  • Deploy continuous network‑traffic analysis that can detect anomalous reverse‑SSH tunnels and unauthorized backdoor activity.
  • Incorporate the new threat indicators into your incident‑response playbooks and vendor‑risk assessments.

Source: The Record

Technical Notes

  • Malware: TwoStroke‑style backdoor, reverse‑SSH tunneling tool.
  • Attack vector: Malware‑based remote‑access (reverse SSH).
  • No CVE identifiers; the threat stems from custom tooling.

Source: The Record

📰 Original Source
https://therecord.media/iran-linked-hackers-expand-infrastructure-europe-middle-east ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →