Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [incident, nation-state, threat-intel, campaign] ยท confidence: high ยท affected_sectors: [defence, technology] ยท au_impact: true

Iran-Linked Tortoiseshell Expands Infrastructure Across Europe and the Middle East

Group-IB identified new infrastructure tied to Tortoiseshell, an Iranian APT linked by researchers to the Islamic Revolutionary Guard Corps, active since at least 2018 and running espionage against defence, aerospace, technology and military organisations. New infrastructure spans Britain (two servers, "uk1" and "uk2"), Belgium, Saudi Arabia and the UAE, alongside new samples of a TwoStroke-like backdoor and a reverse-SSH tunneller.

Attribute Detail
Date 2026-08-26
Actor Tortoiseshell (IRGC-linked)
Infrastructure UK, Belgium, Saudi Arabia, UAE
Tools TwoStroke-like backdoor; reverse-SSH tunneller
Source The Record / Group-IB โ€” Tier 2/4

The widening geography and toolset suggest Tortoiseshell โ€” among the most active Iranian APTs of 2026 โ€” is expanding both reach and capability, in line with elevated Iranian intrusion activity following the MOIS crew sanctions of the same period.

Source