OTX-6a8f1fe0b63c473eb499fd00
info
📛 Threat Title
Expands Toolset With New Backdoor, SSH Tunnel
Description
An Iranian-linked cyber-espionage group known as Tortoiseshell has enhanced its malware arsenal with newly identified tools, including a reverse SSH tunneling utility and a C++ backdoor. The SSH tunnel, disguised as wtsapi32.dll, leverages Windows OpenSSH client to establish connections with command-and-control infrastructure. The backdoor, showing similarities to TWOSTROKE malware, supports file execution, shell commands, in-memory DLL execution, and file manipulation capabilities. Infrastructure analysis revealed domains with subdomains referencing UAE, Saudi Arabia, UK, Belgium, Canada, Australia, and Japan, suggesting expanded targeting beyond the group's traditional focus on defense, aerospace, IT service providers, and military organizations in the Middle East and United States. Active since 2018, the group continues operations with persistent infrastructure despite domain suspensions. Pulse contains 2 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
locat.sbs
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/locat.sbs
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
locat.sbs- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/locat.sbs
domain
tiktok-u.sbs
VT 5 / 91
UrlVoid 1 / 36
IOC database
- Type
- domain
- Value
tiktok-u.sbs- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 5 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Webroot | malicious | malicious |
| alphaMountain.ai | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
| LevelBlue | suspicious | suspicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | sbs |
History
| Creation date | 2026-02-26 00:00 UTC |
| Last analysis | 2026-08-26 17:23 UTC |
| Last modified on VirusTotal | 2026-08-26 19:41 UTC |
| Last WHOIS update | 2026-02-26 00:00 UTC |
| WHOIS record date | 2027-02-26 00:00 UTC |
References (2)
-
OTX pulse
AlienVaulkt OTX
An Iranian-linked cyber-espionage group known as Tortoiseshell has enhanced its malware arsenal with newly identified tools, including a reverse SSH tunneling utility and a C++ backdoor. The SSH tunnel, disguised as wtsapi32.dll, leverages Windows OpenSSH client to establish connections with command-and-control infrastructure. The backdoor, showing similarities to TWOSTROKE malware, supports file execution, shell commands, in-memory DLL execution, and file manipulation capabilities. Infrastructu
- reference AlienVaulkt OTX
Remediations (10)
-
web:cyberpress.org
The toolset effectively turns Windows systems into SSH clients capable of initiating outbound reverse tunnels to attacker-controlled servers, thereby bypassing inbound firewall restrictions. Once active, the malware enables secure SFTP sessions used for stealthy data transfer and continuous operator control.
-
web:cybersecuritynews.com
A new backdoor called PamDOORa has emerged as a serious and growing threat to Linux systems, targeting one of the most trusted components of the operating system to silently steal SSH credentials. The malware was advertised for sale on a Russian-speaking cybercrime forum called Rehub, with its ...
-
web:en.wikipedia.org
A subsequent investigation found that the campaign to insert the backdoor into the XZ Utils project was a culmination of over two years of effort, starting in 2021, by a user going by the name "Jia Tan".
-
web:iplogger.org
Group-IB reveals Tortoiseshell's expanded malware toolset , featuring a new backdoor and stealthy SSH tunneling capabilities.
-
web:radar.offseq.com
Detailed information about Expands Toolset With New Backdoor, SSH Tunnel . Get real-time updates, technical details, and mitigation strategies.
-
web:thehackernews.com
Group-IB uncovers new Nimbus Manticore infrastructure, an SSH tunneler, and a TWOSTROKE-like C++ backdoor across Europe and the Middle East.
-
web:undercodenews.com
On August 26, 2026, Group-IB published new findings showing that the group has expanded its toolkit with previously undocumented malware, including a Windows backdoor and a reverse SSH tunneling utility disguised as a legitimate Windows DLL.
-
web:www.infosecurity-magazine.com
An Iranian-linked threat actor has expanded its malware toolset with a backdoor and reverse SSH tunneling utility, while newly identified infrastructure points to potential targeting across Europe and the Middle East. Group-IB Threat Intelligence began investigating Tortoiseshell after Kaspersky ...
-
web:www.nextron-systems.com
Conclusion The Plague backdoor represents a sophisticated and evolving threat to Linux infrastructure, exploiting core authentication mechanisms to maintain stealth and persistence. Its use of advanced obfuscation, static credentials, and environment tampering makes it particularly difficult to detect using conventional methods.
-
web:www.penligent.ai
CVE-2024-3094 is the XZ Utils liblzma backdoor incident that turned a routine update into a software supply-chain near-miss. This publish-ready guide explains what happened, who was affected, how to verify exposure safely, and how to harden build and artifact trust with practical commands, detection ideas, and a mitigation playbook.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Reputation of linked indicators
DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.
| Indicator | Type | Verdict | Score |
|---|---|---|---|
locat.sbs |
domain | high | 42 |
tiktok-u.sbs |
domain | high | 42 |