UNC3890 is a Mandiant-designated, suspected-Iranian uncategorized cluster active since late 2020 that targets Israeli shipping, government, energy, healthcare, and aviation sectors using social-engineering lures, a shipping-company watering hole, and the custom SUGARUSH backdoor and SUGARDUMP credential stealer.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
UNC3890 was disclosed by Google/Mandiant in August 2022 as an activity cluster that, with moderate confidence, is linked to Iran and has primarily targeted Israeli interests — most notably the shipping sector. The Iran assessment rests on Farsi-language artifacts in the tooling and PDB-path and infrastructure overlaps with UNC2448, an IRGC-affiliated actor; Mandiant deliberately kept the group 'uncategorized' rather than promoting it to a named APT, an uncertainty preserved here.
The group blends espionage with pre-positioning tradecraft. Initial access uses email-borne social-engineering lures (including fake job offers and, notably, a fake robotic-doll advertisement) and a watering hole hosted on the login page of a legitimate Israeli shipping company, designed to harvest credentials from visitors. Post-compromise, UNC3890 deploys two proprietary implants: SUGARUSH, a small backdoor that opens a reverse shell over TCP to a hardcoded C2, and SUGARDUMP, a credential stealer that harvests browser-stored credentials (Chrome, Opera, Edge Chromium) and exfiltrates via legitimate webmail services (Gmail, Yahoo, Yandex).
MENA targeting is Israel-exclusive in the reporting: shipping is the primary vertical, with additional victims in government, energy, healthcare, and aviation — collection that Mandiant assessed could support both intelligence gathering and potential kinetic operations against maritime targets, a concern given contemporaneous Iran-Israel shipping-domain tensions.
UNC3890's last independently confirmed public reporting is Mandiant's August 2022 disclosure, which noted activity ongoing into mid-2022; no distinct UNC3890-branded activity has been prominently re-reported since, so 2022 is treated as its last confirmed active year pending fresh sourcing.