Tortoiseshell APT Expands Toolset With TWOSTROKE Backdoor
The Iranian group Tortoiseshell continues to broaden both its toolset and the geography of its operations. Group-IB specialists have uncovered previously unknown malware samples and additional server infrastructure tied to the group. Among the discoveries were a utility for creating reverse SSH tunnels and a backdoor from the TWOSTROKE family.
Who Tortoiseshell Is
Tortoiseshell, also known as Mirage Kitten, UNC1549, and Nimbus Manticore, has been active since at least 2018. Group-IB links the group to Iran and to the Islamic Revolutionary Guard Corps. Historically, the attackers targeted defense and aerospace companies, military organizations, and IT service providers across the Middle East and the United States. Furthermore, in 2026 Tortoiseshell ranked among the most active Iranian APT groups.
A Reverse SSH Tunnel in Disguise
One of the recovered components masquerades as the Windows system library wtsapi32.dll and establishes a reverse SSH tunnel to an operator server. Consequently, the connection allows traffic from the command server to be redirected into the compromised network. In this way, the approach turns an already-infected computer into an entry point toward other internal resources.
A C++ Backdoor Akin to TWOSTROKE
The second sample proved to be a C++ backdoor closely resembling TWOSTROKE. Like the first, this malicious library poses as wtsapi32.dll and can be loaded by legitimate applications through DLL search-order hijacking. Once launched, the backdoor contacts one of several predefined command servers over HTTPS and awaits operator instructions.
What the Backdoor Can Do
TWOSTROKE can execute programs and shell commands, download and exfiltrate files, run DLLs directly in memory, browse directories, delete files, and gather details about the user and the machine. Notably, for each infected device the malware generates its own identifier based on the machine’s fully qualified network name. Moreover, multiple command-server addresses give the backdoor the ability to switch to a backup node whenever the primary one stops responding.
New Infrastructure Under Scrutiny
The specialists paid particular attention to Tortoiseshell’s new infrastructure. After analysing the associated domains, Group-IB found servers and subdomains bearing labels for the UAE, Saudi Arabia, the United Kingdom, Belgium, Canada, Australia, and Japan. Accordingly, the geography of this infrastructure suggests that the group may be widening its interests across the Middle East and Europe.
Caution Over Attribution
Even so, Group-IB draws no definitive conclusion about the purpose of every discovered server. Since some of the infrastructure has yet to be linked to malicious samples, domain names alone are insufficient to pinpoint specific targets with confidence. Instead, the researchers merely note overlaps between the new infrastructure and nodes that Tortoiseshell used previously.
A Threat Actor Steadily Evolving
According to Group-IB’s assessment, the group continues to refine its means of maintaining a covert presence in networks while simultaneously expanding its operational infrastructure. Ultimately, the combination of SSH tunnels, a multifunctional backdoor, and distributed command servers enables Tortoiseshell to preserve access to infected systems and to conduct prolonged espionage campaigns.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.