UNC1860 is a persistent, opportunistic Iranian state-nexus threat actor assessed to be MOIS-associated. It functions primarily as an initial-access broker and persistence specialist, establishing durable footholds into high-priority Middle Eastern government and telecommunications networks and providing that access to other Iran-linked APTs. It is distinguished by a large repository of custom passive backdoors and specialized tooling, including GUI-operated controllers designed for seamless hand-off to third-party operators unfamiliar with the target environment. Its arsenal reflects strong Windows kernel and reverse-engineering capability, including repurposed legitimate driver code and passive implants that avoid outbound C2 to evade detection.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Mandiant (Google Cloud) publicly detailed UNC1860 in a September 2024 report, drawing on engagements dating to 2019-2020. The actor emphasizes stealthy, long-term persistence: its main-stage passive backdoors (notably TEMPLEDOOR, plus FACEFACE and SPARKLOAD delivered via the low-detection SASHEYAWAY dropper, and kernel-mode implants TOFULOAD/TOFUDRV resembling WINTAPIX) listen passively rather than beaconing outbound, reducing network detection surface. UNC1860 demonstrates deep Windows internals knowledge, repurposing a legitimate Iranian anti-virus driver (Sheed AV) into the TEMPLEDROP filter driver and using event-log tampering utilities (TEMPLELOCK) and custom obfuscation (XORO XOR module, a deliberately misspelled 'bsae64' Base64 DLL) to evade EDR. What most distinguishes UNC1860 operationally is its GUI-operated hand-off toolkit: TEMPLEPLAY (a .NET controller for TEMPLEDOOR supporting command execution, file upload/download, and RDP proxying/forwarding through infected hosts) and VIROGREEN (a framework for exploiting SharePoint CVE-2019-0604 that controls the STAYSHANTE web shell and BASEWALK backdoor). These controllers let other MOIS-associated operators access victim environments without prior familiarity, underscoring UNC1860's role as an access provider. Evidence of the initial-access-broker role includes a 2020 engagement in which UNC1860 leveraged a compromised network to scan and target unrelated entities in Saudi Arabia and Qatar, and command-line tooling used to validate credentials and target VPN servers across Qatari and Saudi entities. Mandiant reports overlaps with APT34 (OilRig): across 2019-2020 engagements, organizations compromised by APT34 were also compromised by UNC1860 and vice versa, with both clusters later pivoting toward Iraq-based targeting, suggesting UNC1860 assists lateral movement and hand-off. UNC1860 also shares targeting and shows parallels with the Shrouded Snooper / Scarred Manticore / Storm-0861 clusters, which have been reported providing access for destructive operations such as BABYWIPER against Israel (October 2023) and ROADSWEEP against Albania (2022) — though Mandiant states it cannot independently corroborate UNC1860's direct involvement in those specific operations. Post-October 2023, UNC1860 tooling gained fresh relevance to Israel-linked network operations: STAYSHANTE and SASHEYAWAY artifacts unique to UNC1860 were identified in a March 2024 wiper campaign flagged by the Israeli National Cyber Directorate that hit Israeli MSPs, local governments, and academia, indicating UNC1860 footholds enabling anti-Israel destructive activity. MENA relevance: HIGH and real. Origin is Iran (assessed MOIS-nexus) — this is the actor's national affiliation, not a target. Its victims/targets are across the Middle East, prominently including Israel (post-Oct-2023 wiper enablement), Iraq (recent operational pivot alongside APT34), plus Saudi Arabia and Qatar. RaqibCTI country tags of 'Israel' and 'Iraq' are valid as TARGET/operational-theater tags but must not be read as origin; the origin_country field (Iran) carries attribution. Recommend adding Iran as an origin tag and, if the tag model distinguishes, marking Israel/Iraq/Saudi Arabia/Qatar as targets.
+1 more relationship — see the relationships browser.