Actor Profile
Nimbus Manticore is an Iranian state-sponsored APT group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Also tracked as GalaxyGato, Mirage Kitten, Screening Serpens, Smoke Sandstorm, Subtle Snail, and UNC1549, the group is assessed to be linked to Tortoiseshell (Imperial Kitten, Unyielding Wasp), which is part of the Charming Kitten (Eclipsed Wasp) cluster. Active since at least July 2018, the group primarily conducts cyber espionage operations and has been identified as among the most active Iranian APT groups in 2026. The actor is motivated by intelligence collection in support of Iranian state interests, particularly targeting defense, aerospace, IT service providers, and military organizations.
TTPs (Tactics, Techniques, Procedures)
The group employs social engineering via Dream Job campaigns for initial access, delivering malware under the pretext of job opportunities. Their toolset includes a C++ backdoor sharing similarities with TWOSTROKE that enables system information collection, DLL loading, file manipulation, and persistence establishment. The backdoor masquerades as wtsapi32.dll and uses hard-coded C2 servers for HTTPS-based command and control. Capabilities include file download/upload, binary/DLL execution, host reconnaissance, directory listing, and file deletion. The group also deploys a reverse SSH tunneling tool masquerading as Windows Terminal Server SDK API, establishing SSH connections to operator infrastructure on port 443. Additional tools include the NightLedger backdoor and custom WebSocket tunnelers (BridgeHead, ArcBridge) for maintaining persistent access to compromised hosts.
Targets & Patterns
Nimbus Manticore primarily targets defense, aerospace, IT service providers, and military organizations. Geographic focus spans the Middle East and the United States, with recently discovered infrastructure suggesting an expanded targeting profile encompassing Middle Eastern countries alongside European nations. Recent campaigns have also targeted entities across the Middle East, Africa, and South Asia. The targeting pattern reflects Iranian intelligence priorities focused on regional adversaries, defense capabilities, and strategic industries that provide insight into military and technological developments relevant to Iranian state interests.
Historical Context
Nimbus Manticore's linked cluster Tortoiseshell has been active since at least July 2018. The group has a documented history of orchestrating Dream Job campaigns, a social engineering technique also employed by other Iranian and North Korean threat actors. Recent reporting from Kaspersky detailed the group's use of NightLedger backdoor and custom WebSocket tunnelers (BridgeHead, ArcBridge) for persistent access. The current findings from Group-IB represent a continuation of the group's toolset evolution, with the TWOSTROKE-like backdoor and SSH tunneler demonstrating ongoing capability development. The discovery of extensive infrastructure spanning Europe and the Middle East indicates geographic expansion beyond historical Middle East and U.S. focus areas.
Defensive Recommendations
- Monitor for suspicious wtsapi32.dll activity and validate legitimate Windows Terminal Server SDK DLL usage to detect backdoor masquerading attempts
- Implement network monitoring for unusual SSH connections on non-standard ports (e.g., port 443) and reverse SSH tunneling behavior indicative of C2 communication
- Deploy behavioral detection for HTTPS C2 beaconing patterns, particularly connections to hard-coded domains with worker thread creation following server responses
- Scrutinize job opportunity-themed communications and recruitment approaches, especially those targeting defense, aerospace, and IT personnel, as potential Dream Job social engineering vectors
- Monitor for file manipulation activities including unauthorized downloads/uploads, DLL loading, and file deletion operations consistent with TWOSTROKE backdoor capabilities
---
# Geopolitical Context
Geopolitical Context
The discovery of expanded infrastructure and new malware variants associated with Nimbus Manticore reflects the sustained evolution of Iran's cyber espionage capabilities under the Islamic Revolutionary Guard Corps (IRGC). The group's activity is consistent with Iran's broader strategic use of cyber operations to monitor regional adversaries and project influence across the Middle East, while extending surveillance reach into Europe. The continued development of custom backdoors and tunneling tools demonstrates institutional investment in maintaining persistent access to targets of strategic interest. The group's affiliation with the Tortoiseshell and Charming Kitten clusters suggests coordination within Iran's layered cyber apparatus, which has historically targeted defense, aerospace, and IT sectors aligned with Tehran's intelligence priorities. The use of social engineering tactics, including job opportunity lures, mirrors techniques employed by other IRGC-linked units to compromise high-value individuals in adversary nations.
State Actor Alignment
Nimbus Manticore is attributed to Iran and assessed to be affiliated with the Islamic Revolutionary Guard Corps (IRGC). The group is linked to Tortoiseshell, which is part of the Charming Kitten cluster—both entities previously associated with Iranian state-sponsored cyber operations. Iran remains subject to comprehensive U.S. and international sanctions, including those targeting the IRGC as a Foreign Terrorist Organization. The group's targeting of defense, aerospace, and military organizations in the Middle East and the United States aligns with Iran's strategic intelligence collection objectives. The discovery of infrastructure spanning Europe and the Middle East suggests an expanded operational footprint consistent with Tehran's efforts to monitor regional adversaries and Western entities with interests in the region.
Business Impacty pro region
The identification of Nimbus Manticore infrastructure across Europe and the Middle East indicates a broadening threat surface for both regions. Middle Eastern nations—particularly Gulf states and Israel—face heightened risk given Iran's longstanding regional rivalries and the group's focus on defense and military sectors. European countries appear to represent emerging targets, potentially reflecting Iranian interest in monitoring diplomatic, defense, or energy sector entities with Middle Eastern exposure or involvement in regional security frameworks. The group's activity may complicate transatlantic cybersecurity coordination, as European organizations increasingly find themselves within the targeting scope of IRGC-linked operations. For the United States, the continued targeting of U.S. entities and the group's use of Dream Job social engineering campaigns underscore persistent threats to defense contractors and technology firms. The expansion of Iranian APT toolsets also raises concerns for regional partners reliant on Western defense and IT infrastructure, as compromised supply chains could enable lateral movement into allied networks.
Forecast
If Nimbus Manticore maintains its current trajectory, the group is likely to remain among the most active Iranian APT actors through 2026 and into 2027, with continued investment in custom malware development and infrastructure expansion. Should geopolitical tensions between Iran and regional adversaries escalate—particularly involving Israel, Saudi Arabia, or the UAE—the group may intensify targeting of defense and critical infrastructure sectors in those nations. If European entities continue to appear in Nimbus Manticore's operational scope, Western cybersecurity agencies may increase threat intelligence sharing and issue joint advisories, potentially leading to additional sanctions designations or indictments targeting IRGC cyber personnel. The group's reliance on social engineering and job-themed lures suggests that organizations in defense, aerospace, and IT services should anticipate sustained spear-phishing campaigns. If attribution becomes more granular and links to specific IRGC units are established, the U.S. and allies may pursue coordinated disruption operations or public attribution campaigns to impose costs on Iranian cyber activity.
