Skip to main content
The Wire
CyberNews by Zentrya One
high Threat Intel

Nimbus Manticore Expands Arsenal With TWOSTROKE-Like Backdoor and SSH Tunneler

The threat actor Nimbus Manticore has expanded its attack toolkit with a new backdoor resembling TWOSTROKE, along with an SSH tunneling utility designed to facilitate covert access and maintain communication with compromised environments.

The newly observed tools indicate an evolution in the group's capabilities, allowing attackers to establish persistent access, tunnel network traffic, and potentially move deeper into targeted environments.

Key Takeaways

  • Nimbus Manticore has added new tools to its malware arsenal.
  • A newly identified backdoor reportedly exhibits similarities to the TWOSTROKE malware family.
  • An SSH tunneler provides attackers with a mechanism for covert network communication and remote access.
  • The expanded toolkit could support persistence, lateral movement, and command-and-control operations.
  • Organizations should closely monitor unusual SSH activity, unauthorized tunneling, and suspicious processes running on servers.

Affected Assets

Asset / System Potential Risk
🖥️ Compromised Servers Installation of backdoors and unauthorized remote access
🔐 SSH Services Abuse for tunneling, persistence, or covert communications
🌐 Network Infrastructure Unauthorized traffic tunneling and potential lateral movement
👤 Privileged Accounts Credential abuse and elevated access
💻 Endpoints & Workstations Malware deployment and initial access
🔗 Internal Services Potential access through compromised hosts and tunnels

Targeted Sector: Various organizations
Threat Actor: Nimbus Manticore
Malware/Tools: TWOSTROKE-like backdoor, SSH tunneler

Threat Actor

Group: Nimbus Manticore

Nimbus Manticore has demonstrated the ability to develop and deploy multiple tools as part of its intrusion operations. The addition of a dedicated backdoor and SSH tunneling capability suggests an effort to improve stealth, persistence, and access within compromised environments.

Why This Matters

Backdoors and tunneling tools can provide threat actors with persistent and relatively discreet access to compromised infrastructure.

The use of SSH-based tunneling is particularly significant because legitimate SSH traffic is common in enterprise environments. Without appropriate monitoring, malicious tunneling activity can potentially blend into normal administrative traffic.

Organizations should therefore pay close attention to unexpected SSH connections, unusual port forwarding, newly created SSH keys, and suspicious processes associated with remote-access services.

Mitigation & Security Recommendations

Organizations should consider the following measures:

  1. Monitor SSH activity

    • Alert on unexpected outbound SSH connections.
    • Monitor unusual SSH sessions, port forwarding, and tunneling activity.
    • Investigate SSH connections to previously unseen external infrastructure.
  2. Secure SSH access

    • Disable password-based SSH authentication where practical.
    • Use strong key-based authentication and MFA for privileged access.
    • Restrict SSH access to authorized management networks.
  3. Monitor for persistence mechanisms

    • Regularly review authorized SSH keys.
    • Monitor changes to SSH configuration files.
    • Investigate unexpected services, scheduled tasks, and startup mechanisms.
  4. Deploy endpoint detection

    • Use EDR/XDR solutions to identify suspicious processes and persistence techniques.
    • Monitor for unusual execution of tunneling utilities and unknown binaries.
  5. Apply network segmentation

    • Restrict communication between critical servers and user networks.
    • Limit outbound connections from sensitive systems.
    • Use firewall controls to prevent unauthorized tunneling.
  6. Strengthen privileged access

    • Apply least-privilege principles.
    • Use PAM for administrative accounts.
    • Regularly review privileged accounts and access permissions.
  7. Conduct threat hunting

    • Search for anomalous SSH connections, unknown binaries, suspicious processes, and unusual network flows.
    • Investigate systems exhibiting unexpected remote-access behavior.

Risk Rating

Threat Severity: High

Primary Risks: Persistent access, network tunneling, credential compromise, lateral movement, and unauthorized remote access.

Bottom Line

The expansion of the Nimbus Manticore toolkit demonstrates how threat actors continue to enhance their ability to maintain stealthy access within compromised environments. The combination of a backdoor and SSH tunneling capability could provide attackers with flexible mechanisms for persistence and covert communications.

Organizations should prioritize SSH monitoring, endpoint detection, privileged-access controls, network segmentation, and proactive threat hunting to identify and disrupt similar activity.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.