Iran-linked hackers expand infrastructure across Europe and Middle East, report says
Group-IB found Iran-linked Tortoiseshell expanding command-and-control infrastructure into the UK, Belgium, Saudi Arabia and the UAE with new malware tooling.
Group-IB researchers identified new Tortoiseshell command-and-control infrastructure, including servers named 'uk1' and 'uk2' hosted on UK IP addresses, plus systems in Belgium, Saudi Arabia and the UAE. The Iran-linked espionage group, active since at least 2018 and previously tied to the Islamic Revolutionary Guard Corps, has historically targeted defense, aerospace, technology and military organizations in the Middle East and the United States. Researchers also uncovered new malware samples, including a backdoor resembling TwoStroke that enables command execution, file theft and system reconnaissance, and a tool establishing reverse SSH tunnels to attacker-controlled servers. Group-IB assesses that the group is expanding both its geographic reach and its capabilities and ranks it among the most active Iranian APTs of 2026.