Iran-linked Tortoiseshell expands hacking infrastructure into the UK, Belgium, Saudi Arabia, and the UAE

Researchers say the Iran-linked espionage group Tortoiseshell has expanded its hacking infrastructure into the UK and other countries, potentially broadening who it can target. Group-IB identified servers and domains tied to the group in Britain, Belgium, Saudi Arabia, and the United Arab Emirates, plus new malware samples including a TwoStroke-like backdoor and a reverse SSH tunnel tool that can give attackers remote control and hidden access into victim networks.
Why it matters: Organizations in defense, aerospace, government, and technology should treat this as a sign of possible expanded Iranian espionage activity and review detections for Tortoiseshell tooling and infrastructure. The practical action is to hunt for the backdoor and reverse tunnel behavior, especially in networks with Middle East or Europe exposure.

Sources

Iran-linked hackers expand infrastructure across Europe and Middle East, report says
2026.08.26 100% relevant
This article establishes a distinct new development: newly identified Tortoiseshell infrastructure in additional countries and fresh malware samples indicating expanded geographic reach and ongoing operational capability.
← Back to all stories