This APT actor has recently deployed servers and domain names linked to several countries in Europe and the Middle East, including the United Kingdom, Belgium, Saudi Arabia and the United Arab Emirates.

Cybersecurity company Group-IB reported on 26 August 2026 that Tortoiseshell, an Iran-linked APT group, had recently expanded its infrastructure into new countries across Europe and the Middle East. Researchers notably identified servers and domain names associated with the United Kingdom, Belgium, Saudi Arabia and the United Arab Emirates.

Group-IB also uncovered new malware samples linked to Tortoiseshell, including a backdoor and a tool designed to establish a reverse SSH tunnel. According to the researchers, these findings suggest that the group is expanding both the scope of its operations and its technical capabilities.

Active since at least 2018, Tortoiseshell is believed to conduct cyberespionage operations on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC). The APT group targets organisations in the defence, aerospace and information technology sectors, particularly in the Middle East and the United States.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.