Expansion of Iranian-linked Malware Toolkit Raises Concerns in Europe and the Middle East
A recent analysis has revealed that a cyber-espionage group with links to Iran, known as Tortoiseshell, has significantly expanded its toolkit of malware. This includes the addition of a sophisticated backdoor and a reverse SSH tunneling utility, two developments that raise alarms about potential targeting across Europe and the Middle East.
The investigation into Tortoiseshell was initiated by Group-IB Threat Intelligence, in response to findings published by Kaspersky in July. The research uncovered new infrastructure associated with this group, along with additional malware samples that had not been previously reported. With the increasing sophistication of cyber threats, the need for vigilance in cybersecurity protocols has never been more critical.
Tortoiseshell, also referred to as Mirage Kitten by Kaspersky, has been active since at least 2018. The group primarily focuses on sectors such as defense, aerospace, IT service providers, and military organizations, especially within the Middle East and the United States. The threat landscape presented by Tortoiseshell is particularly concerning given its history of targeting sensitive and high-stakes organizations.
New Malware Capabilities: Backdoor and SSH Tunnel
One of the newly identified malware samples functions as a reverse SSH tunneling utility. This utility, cleverly disguised as the Windows Terminal Server API DLL known as wtsapi32.dll, allows for the forward-exporting of legitimate functions while utilizing Windows’ OpenSSH client. This dual functionality enables the malware to connect back to Tortoiseshell’s established infrastructure. The significance of this reverse SSH tunnel lies in its ability to redirect traffic from the command-and-control (C2) server directly into compromised networks, providing an avenue for further exploitation.
Additionally, a second sample was identified as a C++ backdoor, which exhibits similarities to TWOSTROKE malware documented by Google Threat Intelligence Group (GTIG) as recently as late 2025. Like its counterpart, this backdoor was also disguised as wtsapi32.dll and was designed to be loaded through a process known as DLL search-order hijacking. Such techniques reveal the advanced methods employed by Tortoiseshell to infiltrate targeted systems unnoticed.
Once established, the backdoor enables HTTPS communication with multiple hardcoded C2 servers. A unique identifier is generated from the compromised system’s fully qualified hostname, facilitating tailored attacks. The capabilities of this backdoor are extensive, including file and shell command executions, in-memory DLL execution, file transfers, directory listings, and even file deletions.
Broader Implications: Expanded Targeting Infrastructure
Alongside the identification of new malware samples, Group-IB has also uncovered infrastructure associated with a previously known Tortoiseshell C2 domain. Two domains—locat[.]sbs and tiktok-u[.]sbs—resolved to related servers. These domains contained subdomains that employed identifiers linked to various countries, including the UAE, Saudi Arabia, the UK, Belgium, Canada, Australia, and Japan. The presence of such diverse subdomains hints at a significantly wider targeting profile, potentially encompassing a range of nations in the Middle East and Europe.
However, Group-IB has noted that while the infrastructure suggests expanded ambitions, the actual use of these servers remains unclear, as researchers have not yet connected any related malware samples to these domains. The ambiguity surrounding this infrastructure underscores the unpredictable nature of cyber threats.
Even after the registrar suspended the tiktok-u[.]sbs domain, the servers continued to remain operational, demonstrating the resilience and adaptability of the Tortoiseshell group. Historical DNS data indicates that its subdomains had previously resolved to the same servers as those associated with locat[.]sbs, indicating a robustly entrenched system likely crafted for a protracted offensive.
Recommendations for Defense
In light of these findings, cybersecurity experts, including those at Group-IB, recommend persistent threat hunting and proactive monitoring of unusual activities associated with wtsapi32.dll side-loading. Organizations should remain vigilant for outbound traffic associated with known Tortoiseshell infrastructures to mitigate the risks posed by this emerging threat.
As the cyber landscape evolves, the challenges presented by sophisticated groups like Tortoiseshell will require enhanced defensive measures and a unified approach to cybersecurity among affected nations and sectors. The implications of such activities are profound, affecting not only individual organizations but also national security and international relations. The ongoing trend of malware sophistication and the geographical spread of targets highlight the urgent need for collaborative efforts in cybersecurity.

