logo

Iran-linked hackers expand infrastructure across Europe and Middle East, report says

ID: e9f9553a-ebda-5e3a-acd0-a599b3b9c1c8

STIX ID: report--e9f9553a-ebda-5e3a-acd0-a599b3b9c1c8

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

...
...

Group-IB researchers linked new servers and domains in the UK, Belgium, Saudi Arabia and the UAE to the Iranian APT 'Tortoiseshell', and identified new malware samples including a TwoStroke-like backdoor and a reverse SSH tunnel tool, suggesting the group is expanding its geographic reach and maintaining sophisticated espionage capabilities against defense, aerospace, and technology targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.