logo

Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool

ID: 882c72c8-026e-5a35-8c2e-a3d90fc28858

STIX ID: report--882c72c8-026e-5a35-8c2e-a3d90fc28858

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-08-26

Date Updated: 2026-08-27

...
...

Group-IB (citing Kaspersky) reports that the Iranian-linked APT Tortoiseshell (Mirage Kitten) has expanded its toolkit with a new Windows Terminal Server API DLL backdoor and a reverse SSH tunneling utility, enabling covert command-and-control and traffic redirection; the actor has targeted defense and aerospace sectors since at least 2018, is linked to Iran's IRGC, and is reportedly broadening operations into Europe and the Middle East.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.