logo

Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel

ID: 532fb7b0-eb1f-55cf-b33f-e76d91d49442

STIX ID: report--532fb7b0-eb1f-55cf-b33f-e76d91d49442

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

...
...

Group-IB reported that Iranian-linked APT Tortoiseshell expanded its toolset with a reverse SSH tunneling utility and a C++ backdoor, both disguised as wtsapi32.dll to enable DLL side-loading; the backdoor supports HTTPS C2, file/shell commands and in-memory DLL execution. Related infrastructure (domains and country-specific subdomains) resolved to active servers spanning the Middle East and Europe, suggesting wider targeting, and researchers recommend persistent hunting for wtsapi32.dll side-loading and monitoring outbound traffic to known C2s.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.