An advanced persistent threat (APT) group, likely affiliated with Iran’s Ministry of Intelligence and Security (MOIS), has emerged as a key player in providing remote access to compromised networks. This group, tracked by Mandiant as UNC1860, shares similarities with other threat clusters monitored by Microsoft (Storm-0861), Cisco Talos, and Check Point (ShroudedSnooper, Scarred Manticore).
"A key characteristic of UNC1860 is its collection of specialized tools and passive backdoors," Mandiant said, "which enable it to act as an initial access provider and maintain persistent access to high-value networks, especially in government and telecommunications sectors across the Middle East."
UNC1860 first gained attention in July 2022 when it was linked to cyberattacks in Albania. These attacks involved a ransomware strain called ROADSWEEP, the CHIMNEYSWEEP backdoor, and the ZEROCLEAR wiper variant. Subsequent attacks targeted both Albania and Israel using new wiper malware dubbed No-Justice and BiBi (aka BABYWIPER).
Mandiant has described UNC1860 as a "formidable threat actor" with a sophisticated toolkit designed to establish footholds within victim networks and maintain long-term access without detection. Among its arsenal are two malware controllers, TEMPLEPLAY and VIROGREEN, which provide Iranian threat actors remote access to compromised environments via the Remote Desktop Protocol (RDP).
These controllers are equipped to deploy custom payloads and perform post-exploitation activities such as internal network scanning. Mandiant has found overlaps between UNC1860 and another Iranian group, APT34 (aka Hazel Sandstorm, Helix Kitten, OilRig), suggesting that both clusters may have targeted the same organizations, particularly in Iraq.
UNC1860's attack strategy typically involves exploiting vulnerabilities in internet-facing servers to drop web shells and malware like STAYSHANTE and SASHEYAWAY. These are used to deploy implants such as TEMPLEDOOR, FACEFACE, and SPARKLOAD, enabling long-term access and data theft.
VIROGREEN, a custom malware framework, has been used to exploit SharePoint vulnerabilities (CVE-2019-0604) and is capable of controlling web shells and backdoors like STAYSHANTE and BASEWALK. TEMPLEPLAY, a .NET-based controller, provides further backdoor capabilities, allowing for command execution, file transfers, and proxy connections to target servers.
UNC1860 has been observed using various tools to achieve its goals, including:
- OATBOAT: A loader for executing shellcode payloads.
- TOFUDRV: A malicious Windows driver similar to WINTAPIX.
- TOFULOAD: A passive implant that communicates via undocumented Input/Output Control (IOCTL) commands.
- TEMPLEDROP: A modified version of Iranian antivirus software, Sheed AV, that protects deployed malware files.
- TEMPLELOCK: A defense evasion tool capable of disabling the Windows Event Log service.
- TUNNELBOI: A network controller for managing remote access and RDP connections.
"As tensions in the Middle East continue to fluctuate, UNC1860’s skill in gaining initial access to critical networks makes it a valuable asset in Iran’s cyber warfare efforts," said researchers Stav Shulman, Matan Mimran, Sarah Bock, and Mark Lechtik.
The threat posed by Iranian cyber actors extends beyond the Middle East. U.S. officials recently disclosed attempts by Iranian hackers to influence upcoming U.S. elections by leaking non-public information from former President Donald Trump’s campaign. Emails containing stolen information were sent to individuals associated with President Biden’s campaign, although there is no indication these recipients responded.
Iran’s cyber operations have increased as tensions rise in the region. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently warned that another Iranian group, Lemon Sandstorm (aka Fox Kitten), has partnered with ransomware groups like NoEscape, RansomHouse, and BlackCat (aka ALPHV) to launch further attacks.
Censys researchers have identified connections between UNC1860 and Lemon Sandstorm based on geolocation, network infrastructure, and other digital fingerprints. "Despite efforts to obscure their activities, human operators often leave patterns," said Matt Lembright of Censys, "whether through their choice of hosting providers, software, or network configurations."