Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC3890

Description

A suspected Iranian threat activity cluster has been linked to attacks aimed at Israeli shipping, government, energy, and healthcare organizations, in a campaign stretching back to late 2020. Researchers believe that the data harvested during the campaign could be used to support various activities. UNC3890, the threat actor behind the attacks, deployed two proprietary pieces of malware – a backdoor named “SUGARUSH” and a browser credential stealer called “SUGARDUMP”, which exfiltrates password information to email addresses registered with Gmail, ProtonMail, Yahoo and Yandex email services. The threat actor also employs a network of C&C servers that host fake login pages impersonating legitimate platforms such as Office 365, LinkedIn and Facebook. These servers are designed to communicate with the targets and also with a watering hole hosted on the login page of a legitimate Israeli shipping company.

AI Analysis

· 2 weeks ago

Executive Summary

UNC3890 is a suspected Iranian threat actor cluster targeting Israeli sectors including shipping, government, energy, and healthcare since late 2020. They deploy SUGARUSH backdoor and SUGARDUMP credential stealer, using phishing and fake login pages to compromise targets.

Goals & Targeting

UNC3890 targets sectors critical to Israel's economy and national security, likely aiming to gather strategic intelligence or disrupt operations. Their focus on energy, healthcare, and shipping suggests an intent to impact both national infrastructure and economic stability. The choice of victims aligns with their suspected affiliation with a nation-state aiming to weaken a geopolitical adversary.

Enhanced Description

UNC3890, likely an Iranian threat group, has been observed targeting critical sectors in Israel through sophisticated campaigns since late 2020. Their operations include deploying custom malware such as SUGARUSH, a backdoor, and SUGARDUMP, a browser credential stealer. The group leverages phishing emails with malicious attachments and fake login pages to compromise targets, exfiltrating sensitive data. This suggests a focus on intelligence gathering or disruption activities. UNC3890's use of Gmail, ProtonMail, Yahoo, and Yandex for C2 communication indicates they target credentials from various services, possibly to maintain persistence and lateral movement within networks.

Key Capabilities

  • Custom malware development (SUGARUSH, SUGARDUMP)
  • Phishing campaigns with malicious attachments
  • Fake login pages impersonating legitimate services
  • Credential exfiltration and data harvesting

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1004
T1078
T1566

Software / Tooling

SUGARUSH
SUGARDUMP

Campaigns & Victims

UNC3890's campaigns are characterized by persistent targeting, likely aiming to maintain long-term presence in targeted networks. Their TTPs indicate a focus on stealth and evasive techniques, possibly to avoid detection by defenders.

IOC Patterns

  • Spear-phishing emails with macro-laced Office documents
  • Fake login pages for legitimate platforms (Office 365, LinkedIn, Facebook)
  • C2 communication via Gmail, ProtonMail accounts

Recommended Actions

  • Implement robust email filtering and detection systems to block phishing attempts.
  • Monitor network traffic for signs of C2 communication patterns.
  • Enforce multi-factor authentication (MFA) on sensitive accounts.
  • Conduct regular security audits and penetration testing to identify vulnerabilities.

Suggested Tags

APT
nation-state
cyber_espionage
shipping
government

Confidence Assessment

Moderate confidence in UNC3890 as a suspected Iranian actor due to their targeting patterns and tools. Limited by lack of official attribution or detailed operational logs beyond researcher observations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Healthcare Targeting
Phishing
Backdoor / C2
Government Targeting
APT
nation-state
cyber_espionage
shipping
government

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.