Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Nimbus Manticore Deploys New TWOSTROKE‑Like Backdoor and SSH Tunneler, Expanding Iranian APT Toolset

Iranian APT group Nimbus Manticore has been observed adding a previously undocumented backdoor resembling TWOSTROKE and an SSH tunneler to its arsenal, enabling stealthy remote access and data exfiltration. This development underscores the need for robust SOC 2 access controls and continuous monitoring to detect unauthorized lateral movement.

LiveThreat™ Intelligence · 📅 August 26, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
thehackernews.com

Nimbus Manticore Deploys New TWOSTROKE‑Like Backdoor and SSH Tunneler, Expanding Iranian APT Toolset

What Happened — Group‑IB researchers uncovered fresh command‑and‑control infrastructure tied to the Iranian state‑sponsored group Nimbus Manticore. The analysis reveals a previously undocumented backdoor that mimics the functionality of the TWOSTROKE malware and an SSH tunneler that provides persistent, encrypted remote access for espionage operations.

Why It Matters for Compliance & Audit Readiness

  • The stealthy backdoor directly challenges SOC 2 access‑control criteria (CC6.1 – CC6.2), which require strict authentication, least‑privilege, and auditable logging of all privileged activity.
  • An SSH tunneler can bypass network segmentation and evade traditional perimeter defenses, making continuous monitoring and immutable log collection essential for a defensible audit trail.
  • Mapping these techniques to your control framework demonstrates due‑diligence to auditors and regulators, reducing risk of non‑compliance findings.

Who Is Affected — Government agencies, critical‑infrastructure operators, and any organization that may be a target of Iranian cyber‑espionage campaigns.

Recommended Actions

  • Align the new backdoor behavior with SOC 2 CC6 controls: enforce MFA for all privileged accounts, enforce least‑privilege, and enable real‑time SSH session logging.
  • Feed the identified Indicators of Compromise (IOCs) into your SIEM/EDR to trigger alerts on anomalous activity.
  • Conduct a control‑gap review to ensure continuous evidence collection for access‑control logs, ready for audit. Source: The Hacker News

Technical Notes

  • Attack vector: Malware – custom backdoor and SSH tunneler.
  • Capabilities: Persistent remote access, encrypted C2, data exfiltration potential.
  • Related tools: TWOSTROKE (reference implementation), custom SSH tunneler. Source: The Hacker News
📰 Original Source
https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →