Iran-linked group hides its backdoor inside a fake Windows DLL

Group-IB has identified new malware samples and new infrastructure tied to Tortoiseshell. The group is Iranian, has been active since at least 2018, and is linked to the Islamic Revolutionary Guard Corps. The findings include a utility that sets up a reverse SSH tunnel and a backdoor resembling the TWOSTROKE family. That backdoor can run commands, move files in and out, and survey the machine it sits on. The infrastructure spans Europe and the Middle East, which Group-IB suggests may point to a widened targeting profile.

Both new samples carry the filename wtsapi32.dll, the name of a genuine Windows library, and both forward the original functions onward so the program loading them notices nothing. One opens a reverse SSH tunnel to the operator's server on port 443, so traffic from the attacker's side emerges inside the compromised network. The other is the backdoor itself, holding three fixed control addresses it moves between when the first does not answer.

Fake wtsapi32.dll Dropped beside the app The app loads it Real functions forwarded SSH tunnel out on 443 Traffic flows inward The file forwards every original function, so the program notices nothing. The backdoor holds three fixed control addresses and moves on when one fails.
Figure: The loading path as Group-IB describes it. The file carries the name of a genuine Windows library and forwards the original functions onward.

What this means for you if you supply defence and aerospace

Group-IB writes that Tortoiseshell has historically gone after defence, aerospace, IT service providers and military organisations, mainly in the Middle East and the United States. What is new is that the infrastructure now stands in Europe too. Our assessment is that you should read this as a signal of direction, not as a warning that you specifically are a target. If you are a subcontractor to the defence sector, you nonetheless sit in the part of the market this group has shown interest in before.

The practical point is the choice of port. The tunnel leaves on 443, the port everything else leaves on as well, and it is established from the inside. A firewall that lets most things out sees nothing wrong. If you have outbound traffic you do not inspect, this is precisely the gap the tool was built for. We think the control lies in knowing which machines have any business speaking SSH out of your network, and in reacting when one of the others does.

Berigo recommends

  • Map which machines have a legitimate reason to open SSH connections outbound. Everything else deserves an alert.
  • Watch for ssh.exe launched from somewhere other than an administrator's terminal, particularly towards port 443.
  • Hunt for wtsapi32.dll in directories where it does not belong, meaning beside an application rather than in the system directory.
  • Treat outbound traffic on 443 as something that has to be explainable, not as something that leaves because the port is always open.
  • If you supply defence or aerospace, put this group into the threat picture you use when you prioritise controls.

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch