TGViewer
Group-IB Group-IB @group_ib · 2.52K subscribers
Post #987 809
🚨Tortoiseshell is evolving its infrastructure and expanding its operational footprint across Europe and the Middle East.

In our latest technical analysis, Group-IB Threat Intelligence uncovered new infrastructure and malware associated with the Iranian-nexus APT, including a reverse SSH tunneling tool disguised as wtsapi32.dll and TWOSTROKE C++ backdoor capable of command execution, file exfiltration, in-memory DLL execution, and host reconnaissance.

Our research also identified additional C2 infrastructure and geographically named subdomains that may indicate a broader targeting profile.

Read the full technical analysis to explore Tortoiseshell's evolving toolset, infrastructure, C2 architecture, and defensive recommendations.

#ThreatIntelligence #APT #CyberSecurity #Tortoiseshell
  • 👍 6
  • 🔥 3
  • ❤ 1
More from @group_ib
  1. Sep 23, 2026🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android bankin…
  2. Sep 17, 2026🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CR…
  3. Sep 14, 2026🚨 Inside the Smishing Triad’s Phishing Cockpit Group-IB’s latest research dives into JWR,…
  4. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  5. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  6. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →