type: incident ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [incident, nation-state, threat-intel, campaign] ยท confidence: high ยท affected_sectors: [defence, technology] ยท au_impact: true
Iran-Linked Tortoiseshell Expands Infrastructure Across Europe and the Middle East
Group-IB identified new infrastructure tied to Tortoiseshell, an Iranian APT linked by researchers to the Islamic Revolutionary Guard Corps, active since at least 2018 and running espionage against defence, aerospace, technology and military organisations. New infrastructure spans Britain (two servers, "uk1" and "uk2"), Belgium, Saudi Arabia and the UAE, alongside new samples of a TwoStroke-like backdoor and a reverse-SSH tunneller.
| Attribute | Detail |
|---|---|
| Date | 2026-08-26 |
| Actor | Tortoiseshell (IRGC-linked) |
| Infrastructure | UK, Belgium, Saudi Arabia, UAE |
| Tools | TwoStroke-like backdoor; reverse-SSH tunneller |
| Source | The Record / Group-IB โ Tier 2/4 |
The widening geography and toolset suggest Tortoiseshell โ among the most active Iranian APTs of 2026 โ is expanding both reach and capability, in line with elevated Iranian intrusion activity following the MOIS crew sanctions of the same period.