HackerFeeds

CyberSecurity News

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

The Hacker News
· August 26, 2026

AI summary

Researchers have found new infrastructure and undocumented malware linked to Nimbus Manticore, a hacking group sponsored by the Iranian state and affiliated with the Islamic Revolutionary Guard Corps. The group is considered one of the most active Iranian advanced persistent threat groups this year. Nimbus Manticore's toolset has been expanded with a backdoor similar to TWOSTROKE and an SSH tunneler. The discovery was made by Group-IB in a recent analysis. Nimbus Manticore is also known by another name, although the details of this alias are not specified. The group's activities are focused on cyber espionage.

Read the full article at The Hacker Newsthehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.