Home/Threat Actor/UNC1860 (Iran MOIS Access Broker)
Threat Actor

UNC1860 (Iran MOIS Access Broker)

unc1860 · iran_state_sponsored_mois_mandiant_high_confidence_unc1860_access_broker · active since 2020-01

UNC1860 is Mandiant's tracked uncategorized threat cluster designation for the Iran/MOIS-affiliated initial access facilitator that provides remote access to high-priority Middle East networks to other Iranian state-sponsored actors per Mandiant canonical disclosure ("UNC1860 is an Iranian state-sponsored threat actor believed to be linked to Iran's Ministry of Intelligence and Security MOIS, known for acting as an initial access provider and its capability to provide access to high-priority networks") with approximately 30 custom malware tools specialized arsenal + TEMPLEDROP Sheed AV Iranian antivirus driver repurposing + TOFUDRV/TOFULOAD undocumented IOCTL passive backdoor evasion + CVE-2019-0604 SharePoint exploitation via VIROGREEN framework + Albania + Israel wiper preparation foothold pattern.

attribution chain via Mandiant canonical September 19 2024 "UNC1860 and the Temple of Oats" disclosure + The Hacker News + Dark Reading canonical Meet UNC1860 Iran's Low-Key Access Broker for State Hackers coverage + SecurityWeek canonical Iranian APT Operating as Initial Access Provider coverage + Security Affairs canonical UNC1860 provides Iran-linked APTs with access coverage + Industrial Cyber + Security Boulevard + NCRI + KPMG industry coverage.

honest attribution caveat UNC1860 is Mandiant uncategorized cluster designation with Mandiant high-confidence Iran/MOIS attribution based on operational pattern overlaps with other Iran- linked clusters Shrouded Snooper + Scarred Manticore + Storm-0861 and targeting consistency with Iranian intelligence priorities.

standalone cluster paralleling unc4990 + teamtnt + confucius in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

operational target profile signature Middle East government + telecommunications + critical infrastructure + media + academia high-priority-networks targeting per Mandiant + signature Iraq + Saudi Arabia + Qatar regional targets per Dark Reading + Mandiant ("UNC1860 has teamed up for attacks against targets in Iraq, Saudi Arabia, and Qatar.

aided in espionage of Mideast telecommunications companies.

prepared the ground for wiper attacks in Albania and Israel") + signature Israel + Albania wiper preparation foothold pattern; operational attack architecture: (1) cluster- defining Iran/MOIS initial access facilitator operational model paralleling KAMACITE Russia access-enablement-team pattern with handoff to APT34/OilRig + Scarred Manticore + Shrouded Snooper + Storm-0861 Iran-linked actors.

(2) cluster-defining 30+ custom malware tools specialized arsenal signature with STAYSHANTE web shell + SASHEYAWAY dropper + TEMPLEDOOR + TEMPLEDROP + TEMPLELOCK + TEMPLEPLAY + VIROGREEN + TOFUDRV + TOFULOAD + TOFUPIPE + OATBOAT + TUNNELBOI + FACEFACE + SPARKLOAD + ROTPIPE custom families.

(3) cluster-defining TEMPLEDROP Sheed AV Iranian antivirus driver repurposing signature distinctive Iranian-software-repurposing tradecraft using legitimate Iranian antivirus Windows file system filter driver to protect deployed files from modification.

(4) cluster-defining TOFUDRV + TOFULOAD + TOFUPIPE undocumented IOCTL passive backdoor evasion tradecraft signature with inbound-only communication via HTTPS-encrypted traffic without initiating outbound connections; (5) cluster-defining TEMPLEPLAY + VIROGREEN GUI-operated malware controllers signature designed to facilitate hand-off operations to other Iranian actors via .NET-based controller for TEMPLEDOOR passive backdoor + custom framework for SharePoint CVE-2019-0604 exploitation.

(6) cluster-defining CVE-2019-0604 SharePoint exploitation binding via VIROGREEN custom framework providing vulnerability scanning + payload control + backdoor deployment + command execution + file download/upload capabilities; (7) cluster-defining APT34/OilRig + Scarred Manticore + Shrouded Snooper + Storm-0861 operational handoff signature with organizations compromised by APT34 in 2019-2020 previously breached by UNC1860 establishing initial-access- handoff-to-APT34 operational pattern + APT34 cluster shifting focus toward Iraq-based targets paralleling UNC1860 regional shift.

(8) cluster- defining Albania + Israel destructive-operations preparation foothold signature with UNC1860 "preparing the ground for wiper attacks in Albania and Israel" through pre-positioning operations + Israeli National Cyber Directorate March 2024 identification of wiper activity with indicators including STAYSHANTE + SASHEYAWAY linked to UNC1860.

(9) signature passive-backdoor-arsenal specialization with TUNNELBOI network controller for RDP connection management + OATBOAT shellcode loader + ROTPIPE evasion utility + TEMPLELOCK Windows Event Log service kill capability.

(10) signature operational tradecraft mirroring Shrouded Snooper + Scarred Manticore + Storm-0861 Iran-linked threat groups per Mandiant + Cisco Talos + Check Point + Microsoft cross-vendor tracking establishing Iran-linked-cluster operational-pattern consistency; cluster fills the Mandiant-UNC1860-Iran-MOIS- affiliated-initial-access-facilitator + 30-custom- malware-tools-specialized-arsenal + TEMPLEDROP- TOFUDRV-TOFULOAD-TEMPLEPLAY-VIROGREEN-OATBOAT- TUNNELBOI-STAYSHANTE-SASHEYAWAY-custom-malware- family + CVE-2019-0604-SharePoint-exploitation- signature + Sheed-AV-Iranian-antivirus-driver- repurposing + APT34-OilRig-Scarred-Manticore- Shrouded-Snooper-Storm-0861-operational-handoff + Iraq-Saudi-Arabia-Qatar-Israel-Albania-regional- targeting + September-2024-Mandiant-disclosure position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

canonical illustration of Mandiant high-confidence Iran/ MOIS attribution methodology + initial-access- facilitator operational model + 30+ custom malware tools specialized arsenal + Iranian- antivirus-driver-repurposing tradecraft + undocumented IOCTL passive backdoor evasion + APT34/OilRig handoff pattern + Albania/Israel wiper preparation foothold cited in essentially all subsequent Iran-linked-initial-access-broker industry analyses through 2020-2026 period.

iran_state_sponsored_mois_mandiant_high_confidence_unc1860_access_broker confidence: high 26 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited1

Profile

UNC1860 is Mandiant's tracked uncategorized threat cluster designation for the Iran/MOIS-affiliated initial access facilitator that provides remote access to high-priority Middle East networks to other Iranian state-sponsored actors including APT34/OilRig + Scarred Manticore + Shrouded Snooper + Storm-0861, with approximately 30 custom malware tools specialized arsenal + TEMPLEDROP Sheed AV Iranian antivirus driver repurposing + TOFUDRV/TOFULOAD undocumented IOCTL passive backdoor evasion + CVE-2019-0604 SharePoint exploitation via VIROGREEN framework + Albania + Israel wiper preparation foothold. Iran/MOIS high-confidence attribution per Mandiant canonical September 19 2024 disclosure + The Hacker News + Dark Reading + SecurityWeek + Security Affairs + Industrial Cyber + Security Boulevard + KPMG industry coverage. Standalone cluster paralleling unc4990 + teamtnt + confucius in v0.1.178 heterogeneous nation- state + criminal cluster gap-filler cell.

Operational target profile
  • Middle East government + telecommunications signature primary.
  • Iraq + Saudi Arabia + Qatar regional.
  • Israel + Albania wiper preparation foothold.
  • High-priority networks signature targeting Operational attack architecture: (1) Iran/MOIS initial access facilitator operational model (cluster-defining) (2) 30+ custom malware tools specialized arsenal (cluster-defining) (3) TEMPLEDROP Sheed AV Iranian antivirus driver repurposing (cluster-defining) (4) TOFUDRV/TOFULOAD undocumented IOCTL passive backdoor evasion (cluster-defining) (5) TEMPLEPLAY + VIROGREEN GUI controllers for handoff operations (cluster-defining) (6) CVE-2019-0604 SharePoint exploitation (cluster-defining) (7) APT34/OilRig + Scarred Manticore + Shrouded Snooper + Storm-0861 handoff (cluster-defining) (8) Albania + Israel wiper preparation foothold (cluster-defining) The cluster fills the Mandiant-UNC1860-Iran-MOIS- affiliated-initial-access-facilitator + 30-custom- malware-tools-specialized-arsenal + TEMPLEDROP- TOFUDRV-TOFULOAD-TEMPLEPLAY-VIROGREEN-OATBOAT- TUNNELBOI-STAYSHANTE-SASHEYAWAY-custom-malware- family + CVE-2019-0604-SharePoint-exploitation- signature + Sheed-AV-Iranian-antivirus-driver- repurposing + APT34-OilRig-Scarred-Manticore- Shrouded-Snooper-Storm-0861-operational-handoff + Iraq-Saudi-Arabia-Qatar-Israel-Albania-regional- targeting + September-2024-Mandiant-disclosure position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

Aliases

26
unc1860unc_1860unc1860 activity clustermandiant unc1860 trackingunc1860 iran mois access brokerunc1860 ministry of intelligence and security iranunc1860 iranian initial access facilitatorunc1860 templedoor templedrop templelock backdoor familyunc1860 templeplay virogreen gui malware controllersunc1860 stayshante sasheyaway web shell dropperunc1860 tofudrv tofuload passive backdoor undocumented ioctlunc1860 oatboat loader shellcode payloadunc1860 tunnelboi network controller rdp managementunc1860 cve-2019-0604 sharepoint exploitationunc1860 sheed av iranian antivirus driver repurposingunc1860 shroudedsnooper similar tradecraftunc1860 scarred manticore similar tradecraftunc1860 storm-0861 similar tradecraftunc1860 apt34 oilrig handoff target overlapunc1860 september 2024 mandiant disclosureunc1860 middle east government telecommunications targetingunc1860 iraq saudi arabia qatar targetingunc1860 albania israel wiper preparation footholdshrouded snooper iran-linked overlapscarred manticore iran-linked overlapunc1860 30 custom malware tools arsenal signature

Notable Campaigns

11
2024UNC1860 September 19 2024 Mandiant Canonical Disclosure Signature
2022-2024UNC1860 Albania + Israel Destructive-Operations Preparation Foothold Signature
2020-2026Continued Industry Reference Status (2020-2026)
2020-2024UNC1860 30+ Custom Malware Tools Specialized Arsenal Signature
2020-2024UNC1860 TEMPLEPLAY + VIROGREEN GUI Malware Controllers for Handoff Operations Signature
2020-2024UNC1860 TEMPLEDROP Sheed AV Iranian Antivirus Driver Repurposing Signature
2020-2024UNC1860 TOFUDRV + TOFULOAD Undocumented IOCTL Passive Backdoor Evasion Signature
2020-2024UNC1860 CVE-2019-0604 SharePoint Exploitation Signature
2020-2024UNC1860 Iraq + Saudi Arabia + Qatar Regional Targeting Signature
2020UNC1860 Origin, 2020 Iran/MOIS Initial Access Facilitator
2019-2020UNC1860 APT34/OilRig 2019-2020 Operational Handoff Target Overlap Signature

Attribution & Reporting

Attributed by
Mandiant (canonical UNC1860 Iran/MOIS high-confidence attribution September 2024 disclosure)Mandiant blog "UNC1860 and the Temple of Oats Iran's Hidden Hand in Middle Eastern Networks" (canonical)The Hacker News (canonical Iranian APT UNC1860 Linked to MOIS coverage)Dark Reading / Nate Nelson (canonical Meet UNC1860 Iran's Low-Key Access Broker coverage)SecurityWeek (canonical Iranian APT Operating as Initial Access Provider coverage)Security Affairs / Pierluigi Paganini (canonical UNC1860 provides Iran-linked APTs with access coverage)Industrial Cyber (canonical Google details UNC1860 Iranian state-sponsored coverage)Security Boulevard / Jeffrey Burt (canonical Iranian-Linked Group Facilitates APT Attacks coverage)NCRI (canonical Iran News Google's Mandiant Unit Exposes Iranian Cyber Espionage Group coverage)KPMG (canonical UNC1860 Iranian state sponsored threat actor briefing)
Key reporting
reportMandiant (Sep 19 2024): UNC1860 and the Temple of Oats Iran's Hidden Hand in Middle Eastern Networks, canonical disclosure
reportThe Hacker News: Iranian APT UNC1860 Linked to MOIS Facilitates Cyber Intrusions in Middle East, canonical coverage
reportDark Reading / Nate Nelson: Meet UNC1860 Iran's Low-Key Access Broker for State Hackers, canonical coverage
reportSecurityWeek: Iranian APT Operating as Initial Access Provider, canonical coverage
reportSecurity Affairs / Pierluigi Paganini: UNC1860 provides Iran-linked APTs with access, canonical coverage
reportIndustrial Cyber: Google details UNC1860 Iranian state-sponsored, canonical coverage
reportKPMG (Oct 2024): UNC1860 Iranian state sponsored threat actor briefing

Operational

State sponsor

UNC1860 is Mandiant's tracked uncategorized threat cluster designation for the Iran/MOIS-affiliated initial access facilitator that provides remote access to high-priority Middle East networks to other Iranian state-sponsored actors. Per Mandiant: "UNC1860 is an Iranian state-sponsored threat actor believed to be linked to Iran's Ministry of Intelligence and Security (MOIS), known for acting as an initial access provider and its capability to provide access to high- priority networks." Honest attribution caveat: UNC1860 is Mandiant uncategorized cluster designation with Mandiant high-confidence Iran/MOIS attribution. Mandiant assesses with high confidence MOIS affiliation based on operational pattern overlaps with other Iran-linked clusters (Shrouded Snooper + Scarred Manticore + Storm-0861) and targeting consistency with Iranian intelligence priorities.

Attribution chain: (1) Mandiant canonical September 19 2024 UNC1860 disclosure: Mandiant published "UNC1860 and the Temple of Oats: Iran's Hidden Hand in Middle Eastern Networks" report establishing canonical UNC1860 Iran/MOIS attribution. (2) Initial access facilitator operational model: per Mandiant + Dark Reading + The Hacker News + SecurityWeek: "UNC1860 has been the gateway for attacks by notorious groups like Scarred Manticore and OilRig (aka APT34, Helix Kitten, Cobalt Gypsym, Lyceum, Crambus, or Siamesekitten)... its focus is exclusively on breaching and establishing a foothold in potentially valuable networks across high-value sectors, government, media, academia, critical infrastructure, and particularly telecommunications , then handing over access to other Iranian nation-state actors." (3) 30+ custom malware tools specialized arsenal: per Mandiant + Dark Reading: UNC1860 maintains an arsenal of approximately 30 custom malware tools including STAYSHANTE web shell + SASHEYAWAY dropper + TEMPLEDOOR + TEMPLEDROP + TEMPLELOCK + TEMPLEPLAY + VIROGREEN + TOFUDRV + TOFULOAD + OATBOAT + TUNNELBOI + FACEFACE + SPARKLOAD + ROTPIPE + TOFUPIPE establishing cluster-defining specialized tooling depth. (4) TEMPLEDROP Sheed AV Iranian antivirus driver repurposing: per Mandiant: TEMPLEDROP is a repurposed version of Iranian Sheed AV antivirus software Windows file system filter driver used to protect deployed files from modification, distinctive Iranian-software- repurposing tradecraft.

(5) Passive-backdoor specialization with undocumented IOCTL signature: per Mandiant: TOFUDRV (malicious Windows driver overlapping with WINTAPIX) + TOFULOAD (passive implant) + TOFUPIPE + TOFULOAD employ undocumented Input/ Output Control (IOCTL) commands for inbound-only communication via HTTPS-encrypted traffic without initiating outbound connections, cluster-defining detection-evasion tradecraft. (6) TEMPLEPLAY + VIROGREEN GUI malware controllers for handoff operations: per Mandiant: TEMPLEPLAY (.NET-based controller for TEMPLEDOOR passive backdoor used as middlebox) + VIROGREEN (custom framework to exploit SharePoint CVE-2019-0604 with post-exploitation capabilities), designed to facilitate hand-off operations to other Iranian actors, supporting initial-access-provider role. (7) CVE-2019-0604 SharePoint exploitation signature: per Mandiant: VIROGREEN controller provides custom framework to exploit SharePoint servers vulnerable to CVE-2019-0604 establishing cluster-defining CVE-binding signature.

(8) APT34/OilRig + Scarred Manticore + Shrouded Snooper + Storm-0861 operational handoff targets: per Security Affairs + Mandiant: organizations compromised by APT34 in 2019-2020 had also been previously breached by UNC1860 suggesting UNC1860 supports Iranian state-sponsored hackers in performing lateral movement. APT34-related clusters and UNC1860 both shifted focus toward Iraq-based targets. (9) March 2024 Israeli National Cyber Directorate wiper IoCs signature: per Security Affairs: Israeli National Cyber Directorate identified wiper activity targeting various sectors in Israel in March 2024 with indicators including STAYSHANTE + SASHEYAWAY linked to UNC1860, establishing wiper-preparation foothold pattern.

(10) Albania + Israel destructive-operations preparation foothold: per Mandiant: UNC1860 "prepared the ground for wiper attacks in Albania and Israel" through pre-positioning operations.

Operational target profile
  • Middle East government signature per Mandiant.
  • Middle East telecommunications signature per Mandiant.
  • Middle East critical infrastructure signature.
  • Middle East media + academia signature.
  • Iraq + Saudi Arabia + Qatar signature regional targets.
  • Israel wiper preparation foothold signature.
  • Albania wiper preparation foothold signature.
  • High-priority networks signature targeting The cluster fills the Mandiant-UNC1860-Iran-MOIS- affiliated-initial-access-facilitator + 30-custom- malware-tools-specialized-arsenal + TEMPLEDROP- TOFUDRV-TOFULOAD-TEMPLEPLAY-VIROGREEN-OATBOAT- TUNNELBOI-STAYSHANTE-SASHEYAWAY-custom-malware- family + CVE-2019-0604-SharePoint-exploitation- signature + Sheed-AV-Iranian-antivirus-driver- repurposing + APT34-OilRig-Scarred-Manticore- Shrouded-Snooper-Storm-0861-operational-handoff + Iraq-Saudi-Arabia-Qatar-Israel-Albania-regional- targeting + September-2024-Mandiant-disclosure position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
Motivations
iran_state_sponsored_mois_affiliated_mandiant_high_confidence, initial_access_facilitator_operational_model_signature, 30_custom_malware_tools_specialized_arsenal_signature, passive_backdoor_undocumented_ioctl_evasion_signature, sheed_av_iranian_antivirus_driver_repurposing_signature, apt34_oilrig_scarred_manticore_shrouded_snooper_handoff_signature, middle_east_government_telecommunications_targeting_signature, albania_israel_wiper_preparation_foothold_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)32/60 · 53%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MOIS MINISTRY OF INTELLIGENCE AND SECURITY IRAN AFFILIATIONSASHEYAWAY DROPPERSHEED AV IRANIAN ANTIVIRUS DRIVER REPURPOSING TRADECRAFTSHROUDED SNOOPER + SCARRED MANTICORE + STORM-0861 OPERATIONAL SIMILARITYSPARKLOAD PAYLOADSTAYSHANTE WEB SHELL

CVEs Exploited

1
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin