UNC1860
Repository Navigation
- Actor workbench: UNC1860
- TTP-to-detection matrix: all mapped techniques
- Surface and capability routes: OT, PLC, HMI, And Exposed Engineering Interfaces; Internet-Facing Servers, Webshells, And Passive Access
- Detection status: dashboard
- Hunt workflow: hunt workflow
- ATT&CK mappings: T1190 Exploit Public-Facing Application (M2); T1505.003 Web Shell (M2); T1105 Ingress Tool Transfer (M2); T1021.001 Remote Services: RDP (M2); T1078 Valid Accounts (M2)
- Mapped detections: DET-003 Unitronics PLC HMI Web Interface Access (Hunt, DRL-4)
- Mapped hunts: HUNT-003 If exposed PLC/HMI surfaces are targeted then OT management paths or ports will show external access
- IOC reference sources:
SRC-MALPEDIA-UNC1860Associated malware families; references; taxonomy;SRC-MANDIANT-UNC1860Tooling; passive backdoors; webshells; access-enablement references - Tool detail pages:
TEMPLEDOOR;TEMPLEPLAY;CRYPTOSLAY;PipeSnoop;STAYSHANTE;SASHEYAWAY;VIROGREEN;TEMPLEDROP;TEMPLELOCK - Tool matrix: all actor-linked tools (9 mapped tool row(s))
- Evidence records:
EVD-001/CLM-UNC1860-001;EVD-008/CLM-UNC1860-002 - Imported research intakes: None currently mapped.
- Intel update candidates: None in current feed pull.
- Source IDs in structured data:
SRC-MALPEDIA-UNC1860,SRC-MANDIANT-UNC1860
UNC1860
Background
UNC1860 is an Iran MOIS-affiliated threat cluster designated and publicly documented by Mandiant in September 2024 through the report "UNC1860 and the Temple of Oats." Prior to public disclosure, the group had been operating quietly in government and telecommunications networks across the Middle East, developing a specialized capability set centered on passive persistence via IIS and web application server implants.
The group's defining characteristic is operational specialization: UNC1860 builds and maintains persistent access footholds that it retains or transfers to other Iran-affiliated actors for follow-on operations. This access-enablement and handoff model positions UNC1860 as an infrastructure provider within the Iranian state actor ecosystem rather than a team that independently conducts espionage or destructive operations end-to-end. Mandiant's reporting framed this explicitly — UNC1860 is a probable initial-access broker whose implanted networks represent positions of opportunity for other threat clusters.
The group's toolset is extensive and custom-built: TEMPLEDOOR, TEMPLEPLAY, CRYPTOSLAY, PipeSnoop, STAYSHANTE, SASHEYAWAY, VIROGREEN, TEMPLEDROP, and TEMPLELOCK are all attributed to this cluster. TEMPLEDOOR functions as a passive backdoor loaded into IIS as a native module — similar to the Liontail framework used by Scarred Manticore, suggesting potential knowledge or tooling transfer between MOIS-affiliated development teams. PipeSnoop, a distinct implant, accepts and executes shellcode received via named pipes — enabling intra-network handoff of capabilities from operators who have domain-level access.
The analytical significance for Israeli government defenders is the handoff model: organizations that detect UNC1860-style webshell or IIS module anomalies should not assume espionage is the end goal. As with Scarred Manticore, confirmed UNC1860 access should be treated as a potential pre-position for destructive operations or intelligence collection by secondary actors who receive transferred access.
Aliases: None confirmed by any vendor. "Temple of Oats" is the title of the Mandiant September 2024 report ("UNC1860 and the Temple of Oats"), not an actor alias — do not record it as one. TEMPLEDOOR, TEMPLEPLAY, and TEMPLEDROP are malware/tool family names associated with this cluster, not actor designations.
Assessed sponsor: Iran state-sponsored, likely MOIS-affiliated in Malpedia and Mandiant-linked reporting.
Relevance
UNC1860 is high priority for Israeli government and public-sector defenders because Malpedia describes it as a persistent and opportunistic Iranian state-sponsored actor likely affiliated with MOIS. The profile highlights specialized tooling and passive backdoors that support persistent access to high-priority Middle Eastern networks, including government and telecommunications.
Mandiant reporting frames UNC1860 as a probable initial access provider with tooling that can enable persistent footholds and handoff-style operations. For Israeli and regional defenders, this means UNC1860 should be treated as an access-enablement and persistence risk even when another persona later conducts espionage, leakage, or destructive activity.
Defensive Focus
- Public-facing edge systems.
- IIS, SharePoint, Exchange, and externally reachable web applications.
- Passive backdoors and webshell-like persistence.
- Government and telecommunications networks.
- Long-lived access that may be handed off to destructive or influence-operation teams.
Associated Families And Tools
Use the generated UNC1860 tool matrix and individual tool pages for behavior, hash/IOC status, sources, and defensive hunting notes:
Detection Ideas
- New or modified files under web roots, SharePoint paths, IIS modules, and application upload directories.
- Web server worker processes spawning shells, scripting engines, or archive tools.
- Long-lived low-volume callbacks from edge servers.
- New local or domain accounts created after public-facing application anomalies.
- RDP, SMB, or WMI activity originating from web servers or DMZ hosts.
- File integrity deviations on internet-facing systems outside approved deployment windows.
Analytic Caution
UNC1860 should not be used as a default attribution label for every Iran-linked webshell. Analysts SHOULD require multiple evidence lines: victimology, specialized tooling, infrastructure, passive backdoor behavior, and source-backed malware-family linkage.
Sources: SRC-MALPEDIA-UNC1860, SRC-MANDIANT-UNC1860.
Public Reports
Primary vendor reporting:
- Mandiant / Google Cloud, "UNC1860 and the Temple of Oats: Iran's Footholds into Critical Networks" — September 2024. Primary public disclosure documenting full toolset (TEMPLEDOOR, TEMPLEPLAY, CRYPTOSLAY, PipeSnoop, STAYSHANTE, SASHEYAWAY, VIROGREEN, TEMPLEDROP, TEMPLELOCK), Middle East government and telecom victimology, and access-broker/handoff model. Source ID
SRC-MANDIANT-UNC1860. - Malpedia, UNC1860 actor profile — Community-maintained actor taxonomy with associated malware family references and cross-vendor alias mapping. Source ID
SRC-MALPEDIA-UNC1860.
Cross-references within repository:
- Actor Profile: Scarred Manticore — Comparable MOIS-affiliated IIS-persistence actor; compare tool families and handoff patterns for detection engineering priority.
- Actor Profile: Void Manticore / Handala — Likely downstream recipient of access established by UNC1860-style initial access operations.