Nimbus Manticore Deploys New TWOSTROKE‑Like Backdoor and SSH Tunneler, Expanding Iranian APT Toolset
What Happened — Group‑IB researchers uncovered fresh command‑and‑control infrastructure tied to the Iranian state‑sponsored group Nimbus Manticore. The analysis reveals a previously undocumented backdoor that mimics the functionality of the TWOSTROKE malware and an SSH tunneler that provides persistent, encrypted remote access for espionage operations.
Why It Matters for Compliance & Audit Readiness
- The stealthy backdoor directly challenges SOC 2 access‑control criteria (CC6.1 – CC6.2), which require strict authentication, least‑privilege, and auditable logging of all privileged activity.
- An SSH tunneler can bypass network segmentation and evade traditional perimeter defenses, making continuous monitoring and immutable log collection essential for a defensible audit trail.
- Mapping these techniques to your control framework demonstrates due‑diligence to auditors and regulators, reducing risk of non‑compliance findings.
Who Is Affected — Government agencies, critical‑infrastructure operators, and any organization that may be a target of Iranian cyber‑espionage campaigns.
Recommended Actions
- Align the new backdoor behavior with SOC 2 CC6 controls: enforce MFA for all privileged accounts, enforce least‑privilege, and enable real‑time SSH session logging.
- Feed the identified Indicators of Compromise (IOCs) into your SIEM/EDR to trigger alerts on anomalous activity.
- Conduct a control‑gap review to ensure continuous evidence collection for access‑control logs, ready for audit. Source: The Hacker News
Technical Notes
- Attack vector: Malware – custom backdoor and SSH tunneler.
- Capabilities: Persistent remote access, encrypted C2, data exfiltration potential.
- Related tools: TWOSTROKE (reference implementation), custom SSH tunneler. Source: The Hacker News