AN Iranian-linked cyber espionage group known as Tortoiseshell has expanded its malware capabilities, introducing a new backdoor and reverse SSH tunneling utility aimed at defense, aerospace, and military sectors primarily in the Middle East and US. Recent investigations by Group-IB Threat Intelligence revealed this group has been active since at least 2018 and identified infrastructure that could indicate a broader targeting range across Europe and the Middle East.
The new malware disguises itself within legitimate Windows system files and allows for various malicious activities including traffic redirection and file manipulation. Group-IB advises enhanced threat monitoring and hunting strategies to counter such threats.