UNC1860 (Iran MOIS Access Broker)
UNC1860 is Mandiant's tracked uncategorized threat cluster designation for the Iran/MOIS-affiliated initial access facilitator that provides remote access to high-priority Middle East networks to other Iranian state-sponsored actors per Mandiant canonical disclosure ("UNC1860 is an Iranian state-sponsored threat actor believed to be linked to Iran's Ministry of Intelligence and Security MOIS, known for acting as an initial access provider and its capability to provide access to high-priority networks") with approximately 30 custom malware tools specialized arsenal + TEMPLEDROP Sheed AV Iranian antivirus driver repurposing + TOFUDRV/TOFULOAD undocumented IOCTL passive backdoor evasion + CVE-2019-0604 SharePoint exploitation via VIROGREEN framework + Albania + Israel wiper preparation foothold pattern.
attribution chain via Mandiant canonical September 19 2024 "UNC1860 and the Temple of Oats" disclosure + The Hacker News + Dark Reading canonical Meet UNC1860 Iran's Low-Key Access Broker for State Hackers coverage + SecurityWeek canonical Iranian APT Operating as Initial Access Provider coverage + Security Affairs canonical UNC1860 provides Iran-linked APTs with access coverage + Industrial Cyber + Security Boulevard + NCRI + KPMG industry coverage.
honest attribution caveat UNC1860 is Mandiant uncategorized cluster designation with Mandiant high-confidence Iran/MOIS attribution based on operational pattern overlaps with other Iran- linked clusters Shrouded Snooper + Scarred Manticore + Storm-0861 and targeting consistency with Iranian intelligence priorities.
standalone cluster paralleling unc4990 + teamtnt + confucius in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
operational target profile signature Middle East government + telecommunications + critical infrastructure + media + academia high-priority-networks targeting per Mandiant + signature Iraq + Saudi Arabia + Qatar regional targets per Dark Reading + Mandiant ("UNC1860 has teamed up for attacks against targets in Iraq, Saudi Arabia, and Qatar.
aided in espionage of Mideast telecommunications companies.
prepared the ground for wiper attacks in Albania and Israel") + signature Israel + Albania wiper preparation foothold pattern; operational attack architecture: (1) cluster- defining Iran/MOIS initial access facilitator operational model paralleling KAMACITE Russia access-enablement-team pattern with handoff to APT34/OilRig + Scarred Manticore + Shrouded Snooper + Storm-0861 Iran-linked actors.
(2) cluster-defining 30+ custom malware tools specialized arsenal signature with STAYSHANTE web shell + SASHEYAWAY dropper + TEMPLEDOOR + TEMPLEDROP + TEMPLELOCK + TEMPLEPLAY + VIROGREEN + TOFUDRV + TOFULOAD + TOFUPIPE + OATBOAT + TUNNELBOI + FACEFACE + SPARKLOAD + ROTPIPE custom families.
(3) cluster-defining TEMPLEDROP Sheed AV Iranian antivirus driver repurposing signature distinctive Iranian-software-repurposing tradecraft using legitimate Iranian antivirus Windows file system filter driver to protect deployed files from modification.
(4) cluster-defining TOFUDRV + TOFULOAD + TOFUPIPE undocumented IOCTL passive backdoor evasion tradecraft signature with inbound-only communication via HTTPS-encrypted traffic without initiating outbound connections; (5) cluster-defining TEMPLEPLAY + VIROGREEN GUI-operated malware controllers signature designed to facilitate hand-off operations to other Iranian actors via .NET-based controller for TEMPLEDOOR passive backdoor + custom framework for SharePoint CVE-2019-0604 exploitation.
(6) cluster-defining CVE-2019-0604 SharePoint exploitation binding via VIROGREEN custom framework providing vulnerability scanning + payload control + backdoor deployment + command execution + file download/upload capabilities; (7) cluster-defining APT34/OilRig + Scarred Manticore + Shrouded Snooper + Storm-0861 operational handoff signature with organizations compromised by APT34 in 2019-2020 previously breached by UNC1860 establishing initial-access- handoff-to-APT34 operational pattern + APT34 cluster shifting focus toward Iraq-based targets paralleling UNC1860 regional shift.
(8) cluster- defining Albania + Israel destructive-operations preparation foothold signature with UNC1860 "preparing the ground for wiper attacks in Albania and Israel" through pre-positioning operations + Israeli National Cyber Directorate March 2024 identification of wiper activity with indicators including STAYSHANTE + SASHEYAWAY linked to UNC1860.
(9) signature passive-backdoor-arsenal specialization with TUNNELBOI network controller for RDP connection management + OATBOAT shellcode loader + ROTPIPE evasion utility + TEMPLELOCK Windows Event Log service kill capability.
(10) signature operational tradecraft mirroring Shrouded Snooper + Scarred Manticore + Storm-0861 Iran-linked threat groups per Mandiant + Cisco Talos + Check Point + Microsoft cross-vendor tracking establishing Iran-linked-cluster operational-pattern consistency; cluster fills the Mandiant-UNC1860-Iran-MOIS- affiliated-initial-access-facilitator + 30-custom- malware-tools-specialized-arsenal + TEMPLEDROP- TOFUDRV-TOFULOAD-TEMPLEPLAY-VIROGREEN-OATBOAT- TUNNELBOI-STAYSHANTE-SASHEYAWAY-custom-malware- family + CVE-2019-0604-SharePoint-exploitation- signature + Sheed-AV-Iranian-antivirus-driver- repurposing + APT34-OilRig-Scarred-Manticore- Shrouded-Snooper-Storm-0861-operational-handoff + Iraq-Saudi-Arabia-Qatar-Israel-Albania-regional- targeting + September-2024-Mandiant-disclosure position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
canonical illustration of Mandiant high-confidence Iran/ MOIS attribution methodology + initial-access- facilitator operational model + 30+ custom malware tools specialized arsenal + Iranian- antivirus-driver-repurposing tradecraft + undocumented IOCTL passive backdoor evasion + APT34/OilRig handoff pattern + Albania/Israel wiper preparation foothold cited in essentially all subsequent Iran-linked-initial-access-broker industry analyses through 2020-2026 period.