Nimbus Manticore, an Iranian state-sponsored hacking group with ties to the Islamic Revolutionary Guard Corps (IRGC), has expanded its malware arsenal with new tools designed for persistent access and lateral movement across compromised networks, according to research published by Group-IB.

The group deployed a previously undocumented backdoor that shares functional similarities with TWOSTROKE, a known command-and-control implant used by Iranian threat actors. Researchers also identified an SSH tunneler component within Nimbus Manticore's toolkit. These additions indicate the group continues to refine its operational capabilities for long-term network persistence and data exfiltration.

Nimbus Manticore ranks among the most active Iranian APT groups operating in 2026, Group-IB's analysis confirms. The collective conducts cyber espionage campaigns targeting government, energy, telecommunications, and defense sectors across the Middle East, South Asia, and parts of Europe. The discovery of new infrastructure and previously unknown malware variants demonstrates the group's ongoing development cycle and commitment to evading detection.

The TWOSTROKE-like backdoor enables remote command execution on compromised hosts. SSH tunnelers allow attackers to establish encrypted communication channels that bypass network perimeter defenses and blend with legitimate traffic. This combination of tools reflects a sophisticated operational approach focused on stealth and sustained access rather than destructive attacks.

The backdoor's functionality aligns with tradecraft observed in other Iranian APT campaigns. Nimbus Manticore operators leverage living-off-the-land techniques, exploiting legitimate system tools and services to minimize forensic footprints. The SSH tunneler component expands their ability to move through internal networks without triggering standard detection mechanisms that flag unusual external communications.

Group-IB's discovery involved analysis of command-and-control infrastructure, malware samples, and operational patterns associated with the group. Researchers traced new infrastructure deployments to previously identified Nimbus Manticore operations, confirming attribution through victimology, targeting patterns, and tool overlap.

Organizations targeted by this group experience extended dwell time before detection. The operators conduct reconnaissance, establish persistence, and exfiltrate data over weeks or months. Critical infrastructure operators in energy and telecommunications sectors should treat Nimbus Manticore activity as a persistent threat requiring continuous network monitoring and incident response readiness.

Network defenders should implement detection signatures for TWOSTROKE-based variants and monitor for unexpected SSH tunnel creation. Logging all outbound SSH connections, particularly those from servers, helps identify lateral movement attempts. Multi-factor authentication, network segmentation, and privileged access management reduce the effectiveness of compromised credentials.

Threat intelligence sharing accelerates detection. Organizations receiving indicators of compromise from Group-IB or US government agencies should integrate those signatures into security information and event management platforms. Regular threat modeling exercises specific to Iranian APT tradecraft prepare security teams for Nimbus Manticore intrusions.

The expansion of this group's malware toolkit reflects the competitive landscape among Iranian cyber operations units. Nimbus Manticore development efforts suggest the group expects to maintain access to high-value targets for extended periods, justifying investment in stealthy, purpose-built tools over commodity malware variants.