HomeCyber BalkansIran-Linked Hackers Utilize Reverse SSH Tunnels to Access Deep Within Compromised Networks

Iran-Linked Hackers Utilize Reverse SSH Tunnels to Access Deep Within Compromised Networks

Published on

spot_img

Tortoiseshell Expands Espionage Toolkit with Advanced Tactics

Recent cybersecurity research has uncovered that Tortoiseshell, an Iran-linked threat actor, is significantly enhancing its espionage capabilities. This group is adopting sophisticated tools, including reverse SSH tunneling utilities, as well as a backdoor reminiscent of TWOSTROKE, aiming to provide operators with covert and persistent access to compromised internal networks.

The investigation initiated following public findings from Kaspersky regarding Mirage Kitten, a related actor divulging insights into a novel malware ecosystem. This ecosystem notably comprises the NightLedger backdoor alongside WebSocket tunneling tools named ArcBridge and BridgeHead. Building upon this foundation, cybersecurity firm Group-IB undertook supplementary investigations, which enriched known indicators of compromise (IOCs) and revealed an extensive infrastructure footprint. As a result, analysts were able to identify previously unreported malware samples and evidence pointing to the persistent development of remote access capabilities and lateral movement tactics.

Tortoiseshell has reportedly been operational since at least 2018 and is primarily focused on entities in the defense, aerospace, IT service sectors, and military-related organizations in both the Middle East and the United States. The group’s activities have included supply-chain compromises, watering-hole attacks, fake recruitment portals, custom malware deployments, and other operations that multiple cybersecurity experts associate with Iranian state interests.

A pivotal discovery in this research was a 64-bit dynamic link library (DLL) called wtsapi32.dll, which masquerades as a legitimate Windows Terminal Server SDK API. This DLL maintains expected application behavior by forwarding legitimate exports, a tactic consistent with DLL search-order hijacking and side-loading techniques. Within its deceptive guise, this implant leverages the native Windows OpenSSH client to establish a reverse SSH tunnel to infrastructure controlled by the attackers, specifically at the IP address 172.86.98.113 over port 443.

The command executed by this malicious software disables host-key verification and employs a remote listener back into the compromised environment through the -R 1081 option. Consequently, connections made to localhost:1081 on the operator’s server can be seamlessly relayed through the encrypted SSH session into the victim’s internal network.

This operational strategy holds considerable significance, as it allows the compromised machine to initiate an outbound encrypted session. This pattern is often more discreet and firewall-friendly, reducing the likelihood of detection compared to exposing a victim host to inbound connections. Interestingly, the Google Threat Intelligence Group previously observed another threat actor, UNC1549, employing similar techniques using reverse SSH tunnels to divert traffic from command and control (C2) infrastructure to victim networks, thereby minimizing actionable host-level forensic evidence during subsequent operations.

Group-IB’s exploration intricately connects the ongoing activities of Tortoiseshell with a cluster of groups also recognized as Mirage Kitten, UNC1549, and Nimbus Manticore. It appears this collective is developing various techniques and tools to further their objectives in cyber-espionage.

In addition to the reverse SSH tunneling capabilities, a second wtsapi32.dll sample has surfaced, displaying strong similarities to TWOSTROKE— a C++ backdoor which Google documented in late 2025. This newly identified malware dynamically resolves Windows APIs, manages communications with C2 servers via WinHTTP, and encrypts sensitive strings at runtime. It creates an identifier unique to its victims based on their fully qualified domain names, applies XOR encryption, and finally sends this data in an HTTPS POST request to its operators.

The identified sample further includes three alternative C2 endpoints: neexportfolio.com, neexportfolio.azurewebsites.net, and neexportfolio.eastus.cloudapp.azure.com. Once an established link is made, the backdoor can issue commands to exfiltrate files, download new payloads, execute command line instructions or shell commands, load DLLs into memory, enumerate directories, gather usernames and hostnames, and even delete files from compromised systems. The specific delimiter used in command fields, @##@, aligns with prior tools attributed to the UNC154 group.

While monitoring vendor access and focusing on cloud-hosted C2 lookalikes, Group-IB also highlights the importance of scrutinizing DLL side-loading behaviors and unexpected local proxy listeners, especially considering how Tortoiseshell intertwines custom implants with authentic Windows components.

Defensive strategies must prioritize the detection of unusual ssh.exe executions on Windows hosts, particularly focusing on reverse forwarding options like -R, outbound SSH connections over port 443, and potential connections to the identified C2 infrastructure. Analysts warn that while infrastructure monitoring alone won’t determine the intended use of these servers, recognizing the geographic naming patterns, server mappings, and continuity of operations is crucial for anticipating future threats posed by Tortoiseshell and its affiliates.

In summary, as Tortoiseshell evolves its toolkit, cybersecurity measures must adapt accordingly, ensuring vigilance against sophisticated infiltration tactics employed by state-sponsored actors such as this one.

Source link

Latest articles

Four in Five AI Tools Operate Without IT Oversight, Research Reveals

Security researchers have raised alarm bells regarding significant deficiencies in information technology oversight, an...

Cyberattack Disrupts Global Operations at Boston Scientific

Massachusetts Cardiac Device Manufacturer Faces Cyberattack Impacting Global Operations Boston Scientific, a prominent cardiac device...

Huntress Reveals Five Instances of North Korean Operatives Posing as Remote IT, Sales, and Healthcare Professionals

North Korean Operatives Posing as Legitimate Workers: A Growing Cybersecurity Threat Cybersecurity firm Huntress has...

More like this

Four in Five AI Tools Operate Without IT Oversight, Research Reveals

Security researchers have raised alarm bells regarding significant deficiencies in information technology oversight, an...

Cyberattack Disrupts Global Operations at Boston Scientific

Massachusetts Cardiac Device Manufacturer Faces Cyberattack Impacting Global Operations Boston Scientific, a prominent cardiac device...