Iran-linked hackers expand infrastructure across Europe and Middle East, report says
Researchers have uncovered new infrastructure linked to an Iranian-linked threat actor that suggests it may be expanding its operations into Britain and other parts of Europe.
The group, known as Tortoiseshell, has been active since at least 2018 and has primarily conducted espionage operations targeting defense, aerospace, technology and military organizations, particularly in the Middle East and the United States.
In a report on Wednesday, researchers at cybersecurity firm Group-IB said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for the group.
In particular, Group-IB found two servers linked to Tortoiseshell, called "uk1" and "uk2," that were hosted on IP addresses in Britain. In a statement to Recorded Future News, researchers said they also identified Tortoiseshell-linked infrastructure in Belgium, Saudi Arabia and the United Arab Emirates.
The purpose of the infrastructure remains unclear, and the country-themed server names alone are not enough to determine whom Tortoiseshell was targeting, the report said.
