Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC1860

Also known as: APT34, TEMPLEPLAY, UNC961, Scarred Manticore, Storm-0861

Description

UNC1860 is a persistent and opportunistic Iranian state-sponsored threat actor that is likely affiliated with Iran’s Ministry of Intelligence and Security (MOIS). A key feature of UNC1860 is its collection of specialized tooling and passive backdoors that Mandiant believes supports several objectives, including its role as a probable initial access provider and its ability to gain persistent access to high-priority networks, such as those in the government and telecommunications space throughout the Middle East.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Critical infrastructure
Energy
Education
Defense
Utilities
Manufacturing
Chemical
Aviation
Oil gas
Healthcare
Hospitality
Information technology
Transportation
Retail
Media

Targeted Countries / Regions

IR
IL
US
SA
IQ
TR
LB
AU
BR

AI Analysis

· 1 week ago

Executive Summary

UNC1860, a persistent Iranian state-sponsored threat actor likely linked to Iran’s Ministry of Intelligence and Security (MOIS), focuses on strategic network intrusions targeting Middle Eastern government and telecommunications sectors. Known for specialized tooling and passive backdoors, UNC1860 is suspected to engage in cyber-espionage and nation-state level cyber activities.

Goals & Targeting

UNC1860 targets Middle Eastern countries, focusing on government and telecommunications networks. The actor likely seeks to obtain sensitive information, disrupt services, or gain strategic advantages for Iran’s foreign policy objectives. Typical victims include high-priority networks in energy, defense, and government sectors, reflecting the group's focus on cyber-espionage and intelligence gathering.

Enhanced Description

UNC1860 represents a significant cyber threat group attributed to Iran, operating with high sophistication in targeting critical infrastructure. The group's primary focus includes gaining unauthorized access to government and telecommunications networks in the Middle East through sophisticated techniques such as spear-phishing campaigns, malware deployment, and persistence mechanisms. UNC1860’s activities are likely state-sponsored, aiming to gather sensitive information and maintain long-term presence within targeted environments. Known for its customized tools and patient attack strategy, the group poses a particular risk to sectors that handle national security and strategic communications.

Key Capabilities

  • State-sponsored activities
  • Cyber-espionage
  • Nation-state level attacks
  • Specialized tooling
  • Passive backdoors
  • Spear-phishing
  • Persistent access

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Exfiltration

ATT&CK Techniques

T1059.003
T1078
T1566.001

Campaigns & Victims

UNC1860 has demonstrated consistent activity across multiple campaigns, targeting high-value Middle Eastern assets with prolonged dwell time. The group’s operations often involve quiet network infiltration and lateral movement to achieve strategic objectives without immediate overt damage.

IOC Patterns

  • Spear-phishing emails
  • Obfuscated scripts or macros in Office documents
  • Encrypted C2 communication channels

Recommended Actions

  • Implement strong email filtering
  • Monitor for unusual network activity
  • Enhance endpoint detection capabilities

Suggested Tags

APT
nation-state
cyber-espionage
Middle East

Confidence Assessment

Confidence is high based on Mandiant’s analysis. However, specific TTPs may vary.

ATT&CK Techniques

Initial Access
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 20

References

  1. apt.etda.or.th — Cited by web research for: APT34
  2. cloud.google.com — Cited by web research for: TEMPLEPLAY
  3. blog.talosintelligence.com — Cited by web research for: UNC961
  4. attack.mitre.org — Cited by web research for: Interception
  5. blog.talosintelligence.com — Cited by web research for: Critical Infrastructure

Intel Summary

1

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

APT
Backdoor / C2
Government Targeting
nation-state
cyber-espionage
Middle East

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.