A suspected Iranian threat activity cluster has been linked to attacks aimed at Israeli shipping, government, energy, and healthcare organizations, in a campaign stretching back to late 2020. Researchers believe that the data harvested during the campaign could be used to support various activities. UNC3890, the threat actor behind the attacks, deployed two proprietary pieces of malware – a backdoor named “SUGARUSH” and a browser credential stealer called “SUGARDUMP”, which exfiltrates password information to email addresses registered with Gmail, ProtonMail, Yahoo and Yandex email services. The threat actor also employs a network of C&C servers that host fake login pages impersonating legitimate platforms such as Office 365, LinkedIn and Facebook. These servers are designed to communicate with the targets and also with a watering hole hosted on the login page of a legitimate Israeli shipping company.
Executive Summary
UNC3890 is a suspected Iranian threat actor cluster targeting Israeli sectors including shipping, government, energy, and healthcare since late 2020. They deploy SUGARUSH backdoor and SUGARDUMP credential stealer, using phishing and fake login pages to compromise targets.
Goals & Targeting
UNC3890 targets sectors critical to Israel's economy and national security, likely aiming to gather strategic intelligence or disrupt operations. Their focus on energy, healthcare, and shipping suggests an intent to impact both national infrastructure and economic stability. The choice of victims aligns with their suspected affiliation with a nation-state aiming to weaken a geopolitical adversary.
Enhanced Description
UNC3890, likely an Iranian threat group, has been observed targeting critical sectors in Israel through sophisticated campaigns since late 2020. Their operations include deploying custom malware such as SUGARUSH, a backdoor, and SUGARDUMP, a browser credential stealer. The group leverages phishing emails with malicious attachments and fake login pages to compromise targets, exfiltrating sensitive data. This suggests a focus on intelligence gathering or disruption activities. UNC3890's use of Gmail, ProtonMail, Yahoo, and Yandex for C2 communication indicates they target credentials from various services, possibly to maintain persistence and lateral movement within networks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC3890's campaigns are characterized by persistent targeting, likely aiming to maintain long-term presence in targeted networks. Their TTPs indicate a focus on stealth and evasive techniques, possibly to avoid detection by defenders.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in UNC3890 as a suspected Iranian actor due to their targeting patterns and tools. Limited by lack of official attribution or detailed operational logs beyond researcher observations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics