APTNimbus Manticore adds a C++ backdoor and an SSH tunneler to its arsenal
On August 26, 2026, Group-IB published a new technical analysis on Nimbus Manticore, an Iranian state-sponsored group affiliated with the IRGC. The actor

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
APTOn August 26, 2026, Group-IB published a new technical analysis on Nimbus Manticore, an Iranian state-sponsored group affiliated with the IRGC. The actor
MalwareSLEEPWALKER is a Windows backdoor that side-loads into ESET agents, listens for encrypted magic packets, and uses multiple transports. No patch exists; mitigation requires IOCs and incident response.
APTCISA red team assessments show varying detection capabilities in critical infrastructures, with both ultimately breached.
MalwareWeedHack malware spreads via fake Minecraft sites post-takedown. Learn about tactics, risks, and protection tips from McAfee.
MalwareToxicPanda 2.0 Android trojan evolves to target corporate identities, using lock screen overlays and backdoors to steal data and gain control.
MalwareA fake 113 GB GTA VI leak contains malware that disables Windows Defender. Learn how cybercriminals exploit hype and avoid traps.
MalwareDiscover SynkLoader, a modular malware that steals passwords via phishing and prepares systems for ransomware attacks. Researchers uncover its deceptive tactics.
APTRecently, Cisco Talos published a two-part analysis of the Chinese-speaking group UAT-10147 , which is active against Windows and Linux web servers on a
MalwareLearn about WordlistLoader and SynkLoader malware that steal credentials and enable network access through phishing and advanced evasion methods.
APTSilkParasite: AI malware targeting Central Asia's economic institutions via spearphishing and Google Drive. Linked to Chinese espionage campaigns.
MalwareNSA, CISA, and FBI warn of ongoing AI-powered attacks on Siemens S7 PLCs in critical infrastructure. Get details on threats, mitigations, and detection.
MalwareDiscover how ToxicPanda 2.0 malware exploits VPN permissions to block Google Play, steal banking credentials, and take control of Android smartphones.