🚨Tortoiseshell is evolving its infrastructure and expanding its operational footprint across Europe and the Middle East.
In our latest technical analysis, Group-IB Threat Intelligence uncovered new infrastructure and malware associated with the Iranian-nexus APT, including a reverse SSH tunneling tool disguised as wtsapi32.dll and TWOSTROKE C++ backdoor capable of command execution, file exfiltration, in-memory DLL execution, and host reconnaissance.
Our research also identified additional C2 infrastructure and geographically named subdomains that may indicate a broader targeting profile.
Read the full technical analysis to explore Tortoiseshell's evolving toolset, infrastructure, C2 architecture, and defensive recommendations.
#ThreatIntelligence #APT #CyberSecurity #Tortoiseshell
Post #987
809

- 👍 6
- 🔥 3
- ❤ 1