Home/Threat Actor/Scarred Manticore
Threat Actor

Scarred Manticore

scarred_manticore_unc1860 · iran · active since 2019-01

Scarred Manticore / UNC1860 is an Iran-aligned cyber espionage cluster with suspected MOIS nexus, active since at least 2019 with primary targeting of Middle Eastern government, defense, and telecommunications organizations across Israel, Jordan, Saudi Arabia, Iraq, and Kuwait.

the cluster is operationally distinctive for its passive-backdoor architecture, the Liontail framework abuses the Windows HTTP.sys kernel driver to register passive HTTP listeners below the user-mode web server process level, providing a detection-resistant C2 channel with no outbound connections.

Mandiant's October 2024 UNC1860 report further assessed the cluster as an initial-access provider within the Iranian threat ecosystem, establishing persistent footholds that are subsequently leveraged by other Iranian- aligned clusters for follow-on espionage or destructive operations.

initial access via N-day exploitation of Microsoft Exchange (ProxyLogon/ProxyShell), Fortinet SSL VPN (CVE-2018-13379), and MSSQL Server.

custom tooling includes Liontail framework, Thandoor, Shikibo, NeoExpress, SpongeSteal, IISSpy IIS-module backdoor, and Pickflux loader.

iran confidence: high 10 aliases

Profile

Scarred Manticore (Check Point Research canonical designation, November 2023) / UNC1860 (Mandiant / Google Threat Intelligence canonical designation, October 2024) is an Iran-aligned cyber espionage cluster with suspected Ministry of Intelligence and Security (MOIS) nexus, active since at least 2019 with primary targeting of Middle Eastern government administrations, telecommunications providers, and critical infrastructure operators across Israel, Jordan, Saudi Arabia, Iraq, Kuwait, and adjacent Gulf states. The cluster is operationally distinctive in two ways that set it apart from the broader Iranian-aligned threat ecosystem: (1) PASSIVE-BACKDOOR ARCHITECTURE AS SIGNATURE TRADECRAFT. The cluster's signature toolset, the Liontail passive backdoor framework, operates via abuse of the Windows HTTP.sys kernel driver to register passive HTTP listeners at the kernel level, below the user-mode web server process level.

This architecture intercepts HTTP traffic containing operator commands before it reaches the user-mode web server, providing a passive-listener command-and-control channel that establishes no outbound network connections to attacker infrastructure and is invisible to standard network-monitoring and endpoint- detection tools that focus on user-mode processes and outbound-connection patterns. The kernel-level passive- listener architecture represents significant technical sophistication and operational-security awareness, the cluster invested in detection-resistant passive-backdoor design rather than the standard active-callback C2 architecture used by most threat actors. An IIS-module-based variant (IISSpy) provides user-mode passive backdoor capability for environments where kernel-driver deployment is not operationally feasible.

Additional custom backdoors (Thandoor, Shikibo, NeoExpress, Pickflux, Tinos, SpongeSteal) documented in the Mandiant UNC1860 report expand the cluster's tooling depth beyond the Liontail framework. (2) INITIAL ACCESS PROVIDER ROLE WITHIN THE IRANIAN ECOSYSTEM. Mandiant's October 2024 UNC1860 report assessed the cluster as an "initial access provider", a cluster whose operational role includes establishing persistent footholds in victim networks and facilitating or providing access to other Iranian threat actor groups for follow-on espionage or destructive operations.

This access-provider role operationally positions Scarred Manticore / UNC1860 as an Iranian-ecosystem-support actor with downstream significance: persistent UNC1860 access in a victim environment may represent a precursor to follow-on operations by other Iranian-aligned clusters including those assessed to conduct destructive operations (such as Agrius, curated at agrius.yaml). The access-provider operational role is uncommon in the Iranian threat ecosystem and analytically significant for understanding how Iranian-aligned clusters coordinate and share operational infrastructure. Initial access tradecraft relies heavily on exploitation of internet-facing applications, Microsoft Exchange (ProxyLogon CVE-2021-26855, ProxyShell CVE-2021-34473), Fortinet SSL VPN (CVE-2018-13379, CVE-2020-12812), Zoho ManageEngine, and MSSQL Server, followed by rapid webshell deployment (ASPXSpy variants, ReGeorg tunneling webshells) for persistent foothold.

The cluster uses N-day vulnerability exploitation rather than zero-day acquisition, consistent with operational positioning as a state-intelligence-resourced actor with access to the N-day exploitation ecosystem but without the resource profile of zero-day-acquisition-capable clusters such as Equation Group or Operation Triangulation. Targeted sectors across the cluster's operational history include government administration (primary), defense and military, telecommunications (analytically significant given intelligence-collection value of telecoms infrastructure), IT services, energy, and diplomatic missions. The targeting geography is strongly Middle East-focused, with Israel and Jordanian government organizations representing the most densely-documented victim environments in public reporting.

Industry attribution to MOIS-nexus Iranian state-aligned operations is analytically consistent across Check Point Research and Mandiant / Google Threat Intelligence, the two primary disclosure vendors. No government cybersecurity authority has formally attributed Scarred Manticore / UNC1860 to a specific MOIS unit or Iranian government ministry. The cluster is analytically distinct from APT34 / OilRig (apt34_oilrig.yaml), MuddyWater (muddywater.yaml), APT35 / Charming Kitten (apt35_charmingkitten.yaml), and Agrius (agrius.yaml), all curated separately, though operational co-presence in shared victim environments has been observed with some adjacent Iranian-aligned clusters.

Aliases

10
scarred_manticorescarred manticoreunc1860unc 1860liontail_operatorsliontail clusterscarredmanticoreiran-mois passive backdoor clusteriran initial access brokermois access provider cluster

Notable Campaigns

4
2024Mandiant / Google Threat Intelligence, UNC1860 Initial Access Provider Role Disclosure (October 2024)
2023Check Point Research Canonical Disclosure, Scarred Manticore (November 2023)
2022-2023Liontail Framework HTTP.sys Kernel-Level Passive Backdoor Architecture
2019-2023Persistent Middle Eastern Government and Telecommunications Espionage (2019-2023)

Attribution & Reporting

Attributed by
Check Point ResearchMandiant (Google Threat Intelligence)Google TAG (Threat Analysis Group)Symantec / Broadcom Threat Hunter TeamESETMicrosoft Threat IntelligenceCrowdStrikeSentinelOneRecorded FutureCisco TalosIsraeli National Cyber Directorate (INCD)CERT-IL (Israeli CERT)Unit 42 (Palo Alto Networks)
Key reporting
reportCheck Point Research: Scarred Manticore, One of the Most Advanced Iranian Espionage Actors (November 2023), canonical first-disclosure
reportMandiant / Google Threat Intelligence: UNC1860, Doorway to Iran's Intelligence Networks (October 2024), canonical UNC1860 / access-provider-role disclosure
reportGoogle TAG: Threat Intelligence Summary, UNC1860 Middle East Targeting
reportIsraeli National Cyber Directorate (INCD): Iran-Aligned Espionage Cluster Advisories
reportMalpedia Actor Profile: Scarred Manticore
reportMalpedia Malware Profiles: Liontail, Thandoor

Operational

State sponsor

Iran-aligned cyber espionage cluster with strong analytical consensus across Check Point Research (canonical Scarred Manticore disclosure, November 2023) and Mandiant / Google Threat Intelligence (canonical UNC1860 disclosure, October 2024) attributing the actor to Iranian state-aligned operations with suspected Ministry of Intelligence and Security (MOIS) nexus. The MOIS nexus assessment is based on targeting profile (overwhelming focus on Middle Eastern governments, telecommunications, and critical infrastructure sectors consistent with Iranian intelligence collection priorities), passive-backdoor operational pattern (consistent with professional intelligence-service tradecraft favoring persistence-and-access over immediate-effect operations), and operational co-presence with other MOIS-assessed Iranian clusters in shared victim environments. Mandiant's UNC1860 October 2024 report assessed the cluster as an "initial access provider", a cluster whose operational role includes establishing persistent footholds in victim networks and providing or facilitating access to other Iranian threat actor groups for follow-on espionage or destructive operations.

The shared-access-provider operational role is distinctive in the Iranian threat ecosystem and operationally distinguishes Scarred Manticore / UNC1860 from single-purpose Iranian espionage clusters. The cluster has not been formally attributed by any government cybersecurity authority to a specific MOIS unit or Iranian government ministry, but the operational pattern is strongly consistent with Iranian state- intelligence priorities and MOIS operational tradecraft. Adjacent Iranian-aligned clusters separately curated in this corpus (apt34_oilrig.yaml, muddywater.yaml, agrius.yaml, unc1860.yaml if separate) share targeting geography with Scarred Manticore but are assessed as operationally distinct clusters with distinct tooling and operational missions.

Motivations
cyber_espionage, initial_access_provision_to_other_iranian_actors, intelligence_collection_on_middle_eastern_governments, telecommunications_and_critical_infrastructure_surveillance, persistent_passive_access_for_follow_on_operations, iranian_state_intelligence_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)32/60 · 53%
Runtime / container (Falco)4/60 · 6%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SHIKIBOSPONGESTEAL
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin