logo

Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks

ID: 52506e50-9257-50c9-904f-00dd51070200

STIX ID: report--52506e50-9257-50c9-904f-00dd51070200

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-08-26

Date Updated: 2026-08-27

Author: Mayura Kathir

...
...

Iran-linked Tortoiseshell (aka Mirage Kitten / UNC1549) is expanding its espionage toolkit with a 64-bit DLL (wtsapi32.dll) that side‑loads and spawns OpenSSH to create reverse SSH tunnels to attacker servers, plus a TWOSTROKE-like WinHTTP backdoor capable of file exfiltration, command execution, DLL loading, and reconnaissance; Group-IB linked new samples and infrastructure (IPs/domains/hashes) and recommends hunting for outbound SSH over 443, ssh.exe with -R, DLL impersonation, and the provided IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.