Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
ID: 882c72c8-026e-5a35-8c2e-a3d90fc28858
STIX ID: report--882c72c8-026e-5a35-8c2e-a3d90fc28858
Feed Name: ThreatCluster
Threat Score
Group-IB (citing Kaspersky) reports that the Iranian-linked APT Tortoiseshell (Mirage Kitten) has expanded its toolkit with a new Windows Terminal Server API DLL backdoor and a reverse SSH tunneling utility, enabling covert command-and-control and traffic redirection; the actor has targeted defense and aerospace sectors since at least 2018, is linked to Iran's IRGC, and is reportedly broadening operations into Europe and the Middle East.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
