Cybersecurity News
Filters
Filtered by tag: espionage × Clear
Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels
Matched: Australia
Iran-linked group Tortoiseshell has expanded espionage operations using a Windows backdoor and reverse SSH tunnelling tool. Both components masquerade as wtsapi32.dll and use DLL hijacking. The backdoor runs commands, transfers files and beacons via HTTPS; the tunnel routes attacker traffic through port 443 into victim networks. Group-IB identified additional infrastructure with country-themed subdomains suggesting targets across the Middle East and Europe.
