Nimbus Manticore Expands Arsenal With TWOSTROKE-Like Backdoor and SSH Tunneler
The threat actor Nimbus Manticore has expanded its attack toolkit with a new backdoor resembling TWOSTROKE, along with an SSH tunneling utility designed to facilitate covert access and maintain communication with compromised environments.

The newly observed tools indicate an evolution in the group's capabilities, allowing attackers to establish persistent access, tunnel network traffic, and potentially move deeper into targeted environments.
Key Takeaways
- Nimbus Manticore has added new tools to its malware arsenal.
- A newly identified backdoor reportedly exhibits similarities to the TWOSTROKE malware family.
- An SSH tunneler provides attackers with a mechanism for covert network communication and remote access.
- The expanded toolkit could support persistence, lateral movement, and command-and-control operations.
- Organizations should closely monitor unusual SSH activity, unauthorized tunneling, and suspicious processes running on servers.
Affected Assets
| Asset / System | Potential Risk |
|---|---|
| 🖥️ Compromised Servers | Installation of backdoors and unauthorized remote access |
| 🔐 SSH Services | Abuse for tunneling, persistence, or covert communications |
| 🌐 Network Infrastructure | Unauthorized traffic tunneling and potential lateral movement |
| 👤 Privileged Accounts | Credential abuse and elevated access |
| 💻 Endpoints & Workstations | Malware deployment and initial access |
| 🔗 Internal Services | Potential access through compromised hosts and tunnels |
Targeted Sector: Various organizations
Threat Actor: Nimbus Manticore
Malware/Tools: TWOSTROKE-like backdoor, SSH tunneler
Threat Actor
Group: Nimbus Manticore
Nimbus Manticore has demonstrated the ability to develop and deploy multiple tools as part of its intrusion operations. The addition of a dedicated backdoor and SSH tunneling capability suggests an effort to improve stealth, persistence, and access within compromised environments.
Why This Matters
Backdoors and tunneling tools can provide threat actors with persistent and relatively discreet access to compromised infrastructure.
The use of SSH-based tunneling is particularly significant because legitimate SSH traffic is common in enterprise environments. Without appropriate monitoring, malicious tunneling activity can potentially blend into normal administrative traffic.
Organizations should therefore pay close attention to unexpected SSH connections, unusual port forwarding, newly created SSH keys, and suspicious processes associated with remote-access services.
Mitigation & Security Recommendations
Organizations should consider the following measures:
Monitor SSH activity
- Alert on unexpected outbound SSH connections.
- Monitor unusual SSH sessions, port forwarding, and tunneling activity.
- Investigate SSH connections to previously unseen external infrastructure.
Secure SSH access
- Disable password-based SSH authentication where practical.
- Use strong key-based authentication and MFA for privileged access.
- Restrict SSH access to authorized management networks.
Monitor for persistence mechanisms
- Regularly review authorized SSH keys.
- Monitor changes to SSH configuration files.
- Investigate unexpected services, scheduled tasks, and startup mechanisms.
Deploy endpoint detection
- Use EDR/XDR solutions to identify suspicious processes and persistence techniques.
- Monitor for unusual execution of tunneling utilities and unknown binaries.
Apply network segmentation
- Restrict communication between critical servers and user networks.
- Limit outbound connections from sensitive systems.
- Use firewall controls to prevent unauthorized tunneling.
Strengthen privileged access
- Apply least-privilege principles.
- Use PAM for administrative accounts.
- Regularly review privileged accounts and access permissions.
Conduct threat hunting
- Search for anomalous SSH connections, unknown binaries, suspicious processes, and unusual network flows.
- Investigate systems exhibiting unexpected remote-access behavior.
Risk Rating
Threat Severity: High
Primary Risks: Persistent access, network tunneling, credential compromise, lateral movement, and unauthorized remote access.
Bottom Line
The expansion of the Nimbus Manticore toolkit demonstrates how threat actors continue to enhance their ability to maintain stealthy access within compromised environments. The combination of a backdoor and SSH tunneling capability could provide attackers with flexible mechanisms for persistence and covert communications.
Organizations should prioritize SSH monitoring, endpoint detection, privileged-access controls, network segmentation, and proactive threat hunting to identify and disrupt similar activity.
Related reporting
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have uncovered a sophisticated banking-malware campaign that hijacks Google Chrome and Microsoft Edge using malicious browser extensions capable of stealing credentials, cookies, session tokens and other sensitive browser data.
UK Government Begins Moving 23 Million Users Away From Passwords With Passkeys
The UK government has begun rolling out passkey authentication to more than 23 million GOV.UK One Login users, marking a major move away from traditional password-based authentication for accessing public services.
WhatsApp Tests Restricted Chat Feature to Keep Sensitive Conversations on Your Primary Phone
WhatsApp is developing a new privacy feature called Restricted Chat that could give users greater control over where sensitive conversations are accessible.


