BTC$84,521-0.54% LTC$68.72+1.12% XMR$536.90-2.07%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Aug 26, 2026 · 2 min read · Original story

Iran-linked hackers expand infrastructure across Europe and Middle East, report says

Iran-linked hackers expand infrastructure across Europe and Middle East, report says
Iran-linked hackers expand infrastructure across Europe and Middle East, report says

Researchers have uncovered new infrastructure linked to an Iranian-linked threat actor that suggests it may be expanding its operations into Britain and other parts of Europe.

The group, known as Tortoiseshell, has been active since at least 2018 and has primarily conducted espionage operations targeting defense, aerospace, technology and military organizations, particularly in the Middle East and the United States.

In a report on Wednesday, researchers at cybersecurity firm Group-IB said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for the group.

In particular, Group-IB found two servers linked to Tortoiseshell, called "uk1" and "uk2," that were hosted on IP addresses in Britain. In a statement to Recorded Future News, researchers said they also identified Tortoiseshell-linked infrastructure in Belgium, Saudi Arabia and the United Arab Emirates.

The purpose of the infrastructure remains unclear, and the country-themed server names alone are not enough to determine whom Tortoiseshell was targeting, the report said.

Researchers also uncovered new samples of malware associated with the group, including a backdoor resembling a tool known as TwoStroke, which was previously documented by Google's threat intelligence researchers in late 2025.

The malware gives hackers broad control over infected computers, allowing them to execute commands, download and steal files, inspect directories and gather information about the targeted machines. The newly discovered sample indicates that Tortoiseshell continues to use the backdoor, according to Group-IB.

Researchers also identified a tool that establishes a so-called reverse SSH tunnel between infected computers and infrastructure controlled by the hackers.

Such tunnels create an encrypted connection from inside a compromised network to an attacker's server, allowing hackers to route traffic back through the infected machine and potentially reach other systems inside the victim's network while bypassing protections designed to block incoming connections.

Group-IB said the combination of newly identified infrastructure and hacking tools suggests Tortoiseshell is expanding both its geographic reach and its capabilities.

Tortoiseshell has previously been linked by cybersecurity researchers to operations supporting Iran's Islamic Revolutionary Guard Corps. Group-IB described it as one of the most active Iranian advanced persistent threat groups operating in 2026.

References in this story

  1. Suspected Iranian cyber-espionage campaign targets Middle East aerospace, defense industries therecord.media An ongoing cyber-espionage campaign that uses unique malware against the aerospace, aviation and defense industries in the Middle East appears to have links to Iran, security researchers say.
  2. Tortoiseshell: New Toolset and Operational Infrastructure Exposed www.group-ib.com Group-IB Threat Intelligence performed enrichment and APT hunting based on recent public data about the Tortoiseshell APT group, leading to the discovery of new samples sharing similarities with known Tortoiseshell…
  3. Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense… cloud.google.com Tactics, techniques and procedures we discovered during incident response investigations into UNC1549 activity.
  4. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  5. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  6. Daryna Antoniuk (@darynant.bsky.social) bsky.app Cybersecurity Reporter at Recorded Future News. Ex at The Kyiv Independent/Forbes/The Kyiv Post 📍Kyiv, Ukraine

← Back to all news