Attribution
Iranian state-nexus threat actor, assessed by Mandiant/Google Cloud with high confidence to be associated with Iran's Ministry of Intelligence and Security (MOIS), based on tradecraft, targeting, and infrastructure/tooling overlaps. Note: 'Scarred Manticore', 'Storm-0861', and 'Shrouded Snooper' are related/overlapping clusters tracked by other vendors, not confirmed 1:1 equivalents; treat as partial overlaps.
First seen
2019 (earliest Mandiant engagements referencing UNC1860 activity are 2019-2020)
Last active
2024 (linked via STAYSHANTE/SASHEYAWAY artifacts to a March 2024 wiper campaign against Israeli entities; Mandiant public report September 2024)
Motivation
Espionage and initial-access brokering / persistence-as-a-service. UNC1860 specializes in gaining and maintaining footholds that are handed off to other MOIS-associated actors, rather than pursuing its own end objectives.
Attribution confidence
high
MENA targeting
Israel, Iraq
Sectors
Government, telecommunications
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Israel, Iraq (Government, telecommunications sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.