Tortoiseshell Adds SSH Tunneling to Its Espionage Kit
Group-IB said on Aug. 26 that Tortoiseshell, also tracked as Mirage Kitten, had added two previously undocumented samples and new infrastructure across Europe and the Middle East. One sample is a reverse SSH tunneler disguised as wtsapi32.dll, and the other is a C++ backdoor that overlaps with TWOSTROKE.
The DLL masquerade matters because Windows can load it like a normal library while the code opens an SSH connection back to operator infrastructure, making the tunnel look like system activity. The backdoor uses the same disguise and can execute commands, move files, and load DLLs, so covert access and persistence are no longer tied to a single implant.
For defenders watching Iranian-linked espionage, the map has shifted from one known toolset to multiple ways of keeping a foothold and routing traffic through a victim host. If your environment sits in defense, aerospace, IT services, or military networks in Europe or the Middle East, the unresolved question is how much of this infrastructure is already in play rather than merely staged.