Also known as: APT34, TEMPLEPLAY, UNC961, Scarred Manticore, Storm-0861
UNC1860 is a persistent and opportunistic Iranian state-sponsored threat actor that is likely affiliated with Iran’s Ministry of Intelligence and Security (MOIS). A key feature of UNC1860 is its collection of specialized tooling and passive backdoors that Mandiant believes supports several objectives, including its role as a probable initial access provider and its ability to gain persistent access to high-priority networks, such as those in the government and telecommunications space throughout the Middle East.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC1860, a persistent Iranian state-sponsored threat actor likely linked to Iran’s Ministry of Intelligence and Security (MOIS), focuses on strategic network intrusions targeting Middle Eastern government and telecommunications sectors. Known for specialized tooling and passive backdoors, UNC1860 is suspected to engage in cyber-espionage and nation-state level cyber activities.
Goals & Targeting
UNC1860 targets Middle Eastern countries, focusing on government and telecommunications networks. The actor likely seeks to obtain sensitive information, disrupt services, or gain strategic advantages for Iran’s foreign policy objectives. Typical victims include high-priority networks in energy, defense, and government sectors, reflecting the group's focus on cyber-espionage and intelligence gathering.
Enhanced Description
UNC1860 represents a significant cyber threat group attributed to Iran, operating with high sophistication in targeting critical infrastructure. The group's primary focus includes gaining unauthorized access to government and telecommunications networks in the Middle East through sophisticated techniques such as spear-phishing campaigns, malware deployment, and persistence mechanisms. UNC1860’s activities are likely state-sponsored, aiming to gather sensitive information and maintain long-term presence within targeted environments. Known for its customized tools and patient attack strategy, the group poses a particular risk to sectors that handle national security and strategic communications.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
UNC1860 has demonstrated consistent activity across multiple campaigns, targeting high-value Middle Eastern assets with prolonged dwell time. The group’s operations often involve quiet network infiltration and lateral movement to achieve strategic objectives without immediate overt damage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is high based on Mandiant’s analysis. However, specific TTPs may vary.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
1
Tactics