TWOSTROKE is a Windows C++ backdoor attributed to the Iranian-nexus threat actor UNC1549, also tracked as Tortoiseshell, Mirage Kitten, and Nimbus Manticore. It is executed through DLL search-order hijacking and masquerades as a legitimate Windows Terminal Server SDK component. The implant uses encrypted runtime strings, derives a victim identifier from host information, and communicates with hard-coded command-and-control servers over encrypted web protocols. TWOSTROKE supports host and user discovery, directory enumeration, file upload and download, data exfiltration, file deletion, shell-command and executable execution, and in-memory DLL execution. It also provides persistence capabilities. UNC1549 has used TWOSTROKE in cyber-espionage operations against defense, aerospace, military, telecommunications, and IT-service-provider organizations, principally in the Middle East and the United States, with indications of broader European interest.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Backdoor TWOSTROKE : DLL GUI 64 bits conçue pour le DLL search-order hijacking. Elle communique en HTTPS avec trois serveurs C2 hardcodés et prend en charge l’exfiltration, l’exécution de commandes ou de DLL en mémoire, le téléchargement de fichiers et la découverte système.
Backdoor TWOSTROKE : DLL GUI 64 bits conçue pour le DLL search-order hijacking. Elle communique en HTTPS avec trois serveurs C2 hardcodés et prend en charge l’exfiltration, l’exécution de commandes ou de DLL en mémoire, le téléchargement de fichiers et la découverte système.
New research uncovered ... a TWOSTROKE-like C++ backdoor capable of reconnaissance, command execution, file upload, and data exfiltration.
Nimbus Manticore ... has been observed using an SSH-based tunneling utility and a C++ backdoor similar to its existing TWOSTROKE implant.
Nimbus Manticore ... has been observed using an SSH-based tunneling utility and a C++ backdoor similar to its existing TWOSTROKE implant.
"TWOSTROKE, a C++ backdoor that allows for system information collection, DLL loading, file manipulation, and persistence"
17 distinct techniques documented for this family, organized by ATT&CK tactic.
« Commandes C2 supportées : ... 1 Exécution de commande shell ou exécutable ».
Supported C2 commands are: Command ID 1: Execute executable file or shell command.
« Stocke les chaînes sensibles chiffrées (stack strings décryptées à l’exécution) ».
The reverse SSH-tunneling tool poses as the Windows Terminal Server SDK API, and the backdoor impersonates the Windows Terminal Server SDK DLL, “wtsapi32.dll.”
Supported C2 commands are: Command ID 4: Get full victim username. | It creates a unique victim identifier ... by calling GetComputerNameExW ... which returns the machine’s fully qualified hostname (Hostname.DomainName).
81 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a malware family overlapping with another Nimbus Manticore backdoor; no further details are supplied.
Backdoor Windows utilisée par Tortoiseshell. Elle emploie le détournement de l’ordre de recherche des DLL, chiffre ses chaînes sensibles et génère un identifiant victime. Ses fonctions C2 incluent l’exfiltration de fichiers, l’exécution de commandes, l’exécution de DLL en mémoire, le téléchargement de charges utiles, ainsi que la collecte des noms d’utilisateur et de machine et le listage de répertoires.
A C++ backdoor used for host reconnaissance, command execution, file uploads, and data exfiltration.
A C++ backdoor/implant attributed to Tortoiseshell that collects system information, loads and executes DLLs or binaries, uploads and downloads files, lists directories, deletes files, and maintains persistence. It communicates with predefined C2 servers over HTTPS and executes operator-provided commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.