Tortoiseshell Adds a wtsapi32 Backdoor and Reverse SSH Tunneller Across Europe and the Gulf
The Iran-linked cluster, also tracked as Mirage Kitten, UNC1549 and Nimbus Manticore, disguised both tools as the Windows Terminal Server DLL for search-order hijacking. Infrastructure nodes spanned the UAE, Saudi Arabia, the United Kingdom, Belgium, Canada, Australia and Japan.