Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1071.001 ↗inferred | Web Protocols | Command and Control | TEMPLEDOOR (.NET) and other main-stage implants are passive backdoors that open an HTTP listener and never initiate outbound C2; commands/payloads carried in HTTPS traffic. |
| T1090.001 ↗inferred | Internal Proxy | Command and Control | TEMPLEPLAY HTTP-proxy tab turns a TEMPLEDOOR host into a proxy so third-party operators can reach internal systems; TUNNELBOI network tunneler establishes remote connections through compromised hosts. |
| T1014 ↗inferred | Rootkit | Defense Evasion | TEMPLEDROP file-system filter driver protects deployed implant files from modification and filters traffic; TOFUDRV/TOFULOAD communicate via undocumented IOCTLs to evade EDR. |
| T1562.002 ↗inferred | Disable Windows Event Logging | Defense Evasion | TEMPLELOCK .NET utility terminates the Windows Event Log service threads and restarts it on demand to suppress logging during operations. |
| T1036.005 ↗inferred | Match Legitimate Name or Location | Defense Evasion | STAYSHANTE web shell and related foothold utilities masquerade with legitimate Windows server file names/dependencies. |
+1 more relationship — see the relationships browser.
| T1027.013 ↗inferred | Encrypted/Encoded File | Defense Evasion | Custom XORO rolling-XOR module and a misspelled custom 'bsae64' encoding DLL reused across SASHEYAWAY, TEMPLEDOOR, TANKSHELL, TUNNELBOI and TEMPLEPLAY instead of built-in .NET crypto; OBFUSLAY/CRYPTOSLAY string decryption. |
| T1059.003 ↗inferred | Windows Command Shell | Execution | TEMPLEPLAY GUI controller exposes a Command Prompt tab that executes cmd commands on TEMPLEDOOR-infected hosts, plus file upload/download. |
| T1078 ↗inferred | Valid Accounts | Initial Access | Observed validating harvested credentials against multiple domains in Saudi Arabia and Qatar using command-line tools before hand-off (2020 engagement). |
| T1190 ↗inferred | Exploit Public-Facing Application | Initial Access | Mandiant 2024: opportunistic exploitation of vulnerable internet-facing servers for footholds; VIROGREEN framework exploits CVE-2019-0604 (SharePoint) and drives post-exploitation payloads. |
| T1021.001 ↗inferred | Remote Desktop Protocol | Lateral Movement | VIROGREEN and TUNNELBOI create RDP connections to internal targets through the proxied foothold, enabling hand-off operators to move laterally. |
| T1543.003 ↗inferred | Windows Service | Persistence | TOFUDRV and TEMPLEDROP Windows kernel drivers (repurposed from a legitimate Iranian Sheed AV filter driver) are installed and loaded as driver services for persistent kernel-level access. |
| T1505.003 ↗inferred | Web Shell | Persistence | STAYSHANTE web shell and SASHEYAWAY dropper planted on compromised servers, controlled via VIROGREEN and left in place for hand-off to other Iranian operators. |
| T1595.001 ↗inferred | Scanning IP Blocks | Reconnaissance | Used compromised Saudi/Qatari victim networks as staging points to scan predominantly Saudi IP ranges and VPN servers for exploitable targets. |
Regional co-occurrence is association, not prediction. These techniques appeared alongside UNC1860's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter UNC1860's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.