Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
ID: 52506e50-9257-50c9-904f-00dd51070200
STIX ID: report--52506e50-9257-50c9-904f-00dd51070200
Feed Name: GBHackers
Iran-linked Tortoiseshell (aka Mirage Kitten / UNC1549) is expanding its espionage toolkit with a 64-bit DLL (wtsapi32.dll) that side‑loads and spawns OpenSSH to create reverse SSH tunnels to attacker servers, plus a TWOSTROKE-like WinHTTP backdoor capable of file exfiltration, command execution, DLL loading, and reconnaissance; Group-IB linked new samples and infrastructure (IPs/domains/hashes) and recommends hunting for outbound SSH over 443, ssh.exe with -R, DLL impersonation, and the provided IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
