hands keyboard
Image: Wesley Tingey via Unsplash

Iran-linked hackers expand infrastructure across Europe and Middle East, report says

Researchers have uncovered new infrastructure linked to an Iranian-linked threat actor that suggests it may be expanding its operations into Britain and other parts of Europe.

The group, known as Tortoiseshell, has been active since at least 2018 and has primarily conducted espionage operations targeting defense, aerospace, technology and military organizations, particularly in the Middle East and the United States.

In a report on Wednesday, researchers at cybersecurity firm Group-IB said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for the group.

In particular, Group-IB found two servers linked to Tortoiseshell, called "uk1" and "uk2," that were hosted on IP addresses in Britain. In a statement to Recorded Future News, researchers said they also identified Tortoiseshell-linked infrastructure in Belgium, Saudi Arabia and the United Arab Emirates.

The purpose of the infrastructure remains unclear, and the country-themed server names alone are not enough to determine whom Tortoiseshell was targeting, the report said.

Researchers also uncovered new samples of malware associated with the group, including a backdoor resembling a tool known as TwoStroke, which was previously documented by Google's threat intelligence researchers in late 2025.

The malware gives hackers broad control over infected computers, allowing them to execute commands, download and steal files, inspect directories and gather information about the targeted machines. The newly discovered sample indicates that Tortoiseshell continues to use the backdoor, according to Group-IB.

Researchers also identified a tool that establishes a so-called reverse SSH tunnel between infected computers and infrastructure controlled by the hackers.

Such tunnels create an encrypted connection from inside a compromised network to an attacker's server, allowing hackers to route traffic back through the infected machine and potentially reach other systems inside the victim's network while bypassing protections designed to block incoming connections.

Group-IB said the combination of newly identified infrastructure and hacking tools suggests Tortoiseshell is expanding both its geographic reach and its capabilities.

Tortoiseshell has previously been linked by cybersecurity researchers to operations supporting Iran's Islamic Revolutionary Guard Corps. Group-IB described it as one of the most active Iranian advanced persistent threat groups operating in 2026.

Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.