s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-6a8f1fe0b63c473eb499fd00 info

📛 Threat Title

Expands Toolset With New Backdoor, SSH Tunnel

Category: Tortoiseshell Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

An Iranian-linked cyber-espionage group known as Tortoiseshell has enhanced its malware arsenal with newly identified tools, including a reverse SSH tunneling utility and a C++ backdoor. The SSH tunnel, disguised as wtsapi32.dll, leverages Windows OpenSSH client to establish connections with command-and-control infrastructure. The backdoor, showing similarities to TWOSTROKE malware, supports file execution, shell commands, in-memory DLL execution, and file manipulation capabilities. Infrastructure analysis revealed domains with subdomains referencing UAE, Saudi Arabia, UK, Belgium, Canada, Australia, and Japan, suggesting expanded targeting beyond the group's traditional focus on defense, aerospace, IT service providers, and military organizations in the Middle East and United States. Active since 2018, the group continues operations with persistent infrastructure despite domain suspensions. Pulse contains 2 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain locat.sbs VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/locat.sbs
UrlVoid 0 / 36

IOC database

Type
domain
Value
locat.sbs
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/locat.sbs

domain tiktok-u.sbs VT 5 / 91 UrlVoid 1 / 36

IOC database

Type
domain
Value
tiktok-u.sbs
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 5 of 91 VirusTotal vendors

VendorVerdictDetection
Webroot malicious malicious
alphaMountain.ai suspicious suspicious
Gridinsoft suspicious suspicious
LevelBlue suspicious suspicious
SOCRadar suspicious suspicious

Details From VirusTotal

Basic Properties
TLDsbs
History
Creation date2026-02-26 00:00 UTC
Last analysis2026-08-26 17:23 UTC
Last modified on VirusTotal2026-08-26 19:41 UTC
Last WHOIS update2026-02-26 00:00 UTC
WHOIS record date2027-02-26 00:00 UTC

References (2)

  • OTX pulse AlienVaulkt OTX

    An Iranian-linked cyber-espionage group known as Tortoiseshell has enhanced its malware arsenal with newly identified tools, including a reverse SSH tunneling utility and a C++ backdoor. The SSH tunnel, disguised as wtsapi32.dll, leverages Windows OpenSSH client to establish connections with command-and-control infrastructure. The backdoor, showing similarities to TWOSTROKE malware, supports file execution, shell commands, in-memory DLL execution, and file manipulation capabilities. Infrastructu

  • reference AlienVaulkt OTX

Remediations (10)

  • web:cyberpress.org

    The toolset effectively turns Windows systems into SSH clients capable of initiating outbound reverse tunnels to attacker-controlled servers, thereby bypassing inbound firewall restrictions. Once active, the malware enables secure SFTP sessions used for stealthy data transfer and continuous operator control.

  • web:cybersecuritynews.com

    A new backdoor called PamDOORa has emerged as a serious and growing threat to Linux systems, targeting one of the most trusted components of the operating system to silently steal SSH credentials. The malware was advertised for sale on a Russian-speaking cybercrime forum called Rehub, with its ...

  • web:en.wikipedia.org

    A subsequent investigation found that the campaign to insert the backdoor into the XZ Utils project was a culmination of over two years of effort, starting in 2021, by a user going by the name "Jia Tan".

  • web:iplogger.org

    Group-IB reveals Tortoiseshell's expanded malware toolset , featuring a new backdoor and stealthy SSH tunneling capabilities.

  • web:radar.offseq.com

    Detailed information about Expands Toolset With New Backdoor, SSH Tunnel . Get real-time updates, technical details, and mitigation strategies.

  • web:thehackernews.com

    Group-IB uncovers new Nimbus Manticore infrastructure, an SSH tunneler, and a TWOSTROKE-like C++ backdoor across Europe and the Middle East.

  • web:undercodenews.com

    On August 26, 2026, Group-IB published new findings showing that the group has expanded its toolkit with previously undocumented malware, including a Windows backdoor and a reverse SSH tunneling utility disguised as a legitimate Windows DLL.

  • web:www.infosecurity-magazine.com

    An Iranian-linked threat actor has expanded its malware toolset with a backdoor and reverse SSH tunneling utility, while newly identified infrastructure points to potential targeting across Europe and the Middle East. Group-IB Threat Intelligence began investigating Tortoiseshell after Kaspersky ...

  • web:www.nextron-systems.com

    Conclusion The Plague backdoor represents a sophisticated and evolving threat to Linux infrastructure, exploiting core authentication mechanisms to maintain stealth and persistence. Its use of advanced obfuscation, static credentials, and environment tampering makes it particularly difficult to detect using conventional methods.

  • web:www.penligent.ai

    CVE-2024-3094 is the XZ Utils liblzma backdoor incident that turned a routine update into a software supply-chain near-miss. This publish-ready guide explains what happened, who was affected, how to verify exposure safely, and how to harden build and artifact trust with practical commands, detection ideas, and a mitigation playbook.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Reputation of linked indicators

DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.

Domains scored
2 / 2
IPs scored
0 / 0
Flagged
2
IndicatorTypeVerdictScore
locat.sbs domain high 42
tiktok-u.sbs domain high 42