UNC1860 is an Iranian MOIS-linked persistent threat actor targeting government and telecom networks in the Middle East.
Analyst brief
UNC1860 is an Iranian state-sponsored persistent threat actor, likely affiliated with Iran's Ministry of Intelligence and Security (MOIS). It primarily targets high-priority networks in the government and telecommunications sectors throughout the Middle East. Its key TTPs involve a collection of specialized tooling and passive backdoors, enabling it to function as an initial access provider and maintain persistent access to compromised environments. Defenders should carefully monitor network traffic for signs of passive backdoors and remain vigilant against targeted phishing and initial access attempts, especially those aimed at government and telecommunications entities in the Middle East.
UNC1860
unknown
UNC1860 is a persistent and opportunistic Iranian state-sponsored threat actor that is likely affiliated with Iran’s Ministry of Intelligence and Security (MOIS). A key feature of UNC1860 is its collection of specialized tooling and passive backdoors that Mandiant believes supports several objectives, including its role as a probable initial access provider and its ability to gain persistent access to high-priority networks, such as those in the government and telecommunications space throughout the Middle East.
UNC1860 primarily targets high-priority networks in the government and telecommunications sectors throughout the Middle East.
What key areas should defenders focus on against UNC1860?+
Defenders should carefully monitor network traffic for signs of passive backdoors and remain vigilant against targeted phishing attempts aimed at government and telecommunications entities.