UNC215 is a Chinese state-nexus cyber espionage cluster first identified by Mandiant (FireEye) responding to intrusions in the Middle East beginning in early 2019. The group exploited a Microsoft SharePoint vulnerability (CVE-2019-0604) to deploy web shells and custom backdoors, running concurrent operations against Israeli government institutions, IT providers, and telecommunications entities. UNC215 is notable for deliberate operational-security and anti-attribution tradecraft, including planting false flags (Farsi-language strings) to misdirect analysts toward Iran, cleaning up post-intrusion evidence, and abusing trusted third-party relationships for lateral movement.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
In early 2019, Mandiant began identifying and responding to intrusions in the Middle East attributed to UNC215. The group exploited the Microsoft SharePoint vulnerability CVE-2019-0604 to install web shells and FOCUSFJORD payloads against targets in the Middle East and Central Asia. Investigation revealed multiple concurrent operations against Israeli government institutions, IT providers, and telecommunications entities beginning in January 2019. UNC215 typically used the FOCUSFJORD backdoor in the initial stages of an intrusion and later deployed HYPERBRO, which added richer collection capabilities such as screen capture and keylogging. The group employed multiple techniques to hinder attribution and detection: cleaning up evidence after gaining access, exploiting trusted third parties for access and lateral movement, making technical modifications to tools to limit outbound network traffic, and planting false flags such as Farsi strings intended to suggest Iranian attribution. Public knowledge of UNC215 rests largely on a single primary source (Mandiant/FireEye's August 2021 report), with secondary press coverage re-reporting those findings; independent corroboration is limited, and the 'UNC' designation reflects Mandiant's uncertainty about full attribution. MENA relevance: HIGH and REAL. Israel is the group's confirmed primary target geography — Mandiant documented sustained, concurrent operations against Israeli government, IT-provider, and telecommunications networks, with additional targeting elsewhere in the Middle East and Central Asia. The RaqibCTI 'Israel' country tag is accurate and evidence-backed. Note the deliberate Iran false-flag element: UNC215 planted Farsi strings and reused Iranian-associated tooling to misdirect attribution, so Iran-nexus signals in related reporting should be treated as intentional deception rather than genuine Iranian activity.