Tortoiseshell expands toolkit with backdoor, SSH tunnel
🛡️ Group-IB identified new Tortoiseshell activity, uncovering a reverse SSH tunneling utility and a C++ backdoor disguised as wtsapi32.dll. The SSH tool leverages Windows OpenSSH to create reverse tunnels into compromised networks, while the backdoor supports HTTPS C2 communications, file and shell execution, and in-memory DLL loading. Researchers also linked domains resolving to servers with regional subdomains, suggesting possible targeting across Europe and the Middle East and urging enhanced threat hunting and monitoring.
