Skip to main content

UNC1860

Repository Navigation

UNC1860

Background

UNC1860 is an Iran MOIS-affiliated threat cluster designated and publicly documented by Mandiant in September 2024 through the report "UNC1860 and the Temple of Oats." Prior to public disclosure, the group had been operating quietly in government and telecommunications networks across the Middle East, developing a specialized capability set centered on passive persistence via IIS and web application server implants.

The group's defining characteristic is operational specialization: UNC1860 builds and maintains persistent access footholds that it retains or transfers to other Iran-affiliated actors for follow-on operations. This access-enablement and handoff model positions UNC1860 as an infrastructure provider within the Iranian state actor ecosystem rather than a team that independently conducts espionage or destructive operations end-to-end. Mandiant's reporting framed this explicitly — UNC1860 is a probable initial-access broker whose implanted networks represent positions of opportunity for other threat clusters.

The group's toolset is extensive and custom-built: TEMPLEDOOR, TEMPLEPLAY, CRYPTOSLAY, PipeSnoop, STAYSHANTE, SASHEYAWAY, VIROGREEN, TEMPLEDROP, and TEMPLELOCK are all attributed to this cluster. TEMPLEDOOR functions as a passive backdoor loaded into IIS as a native module — similar to the Liontail framework used by Scarred Manticore, suggesting potential knowledge or tooling transfer between MOIS-affiliated development teams. PipeSnoop, a distinct implant, accepts and executes shellcode received via named pipes — enabling intra-network handoff of capabilities from operators who have domain-level access.

The analytical significance for Israeli government defenders is the handoff model: organizations that detect UNC1860-style webshell or IIS module anomalies should not assume espionage is the end goal. As with Scarred Manticore, confirmed UNC1860 access should be treated as a potential pre-position for destructive operations or intelligence collection by secondary actors who receive transferred access.

Aliases: None confirmed by any vendor. "Temple of Oats" is the title of the Mandiant September 2024 report ("UNC1860 and the Temple of Oats"), not an actor alias — do not record it as one. TEMPLEDOOR, TEMPLEPLAY, and TEMPLEDROP are malware/tool family names associated with this cluster, not actor designations.

Assessed sponsor: Iran state-sponsored, likely MOIS-affiliated in Malpedia and Mandiant-linked reporting.

Relevance

UNC1860 is high priority for Israeli government and public-sector defenders because Malpedia describes it as a persistent and opportunistic Iranian state-sponsored actor likely affiliated with MOIS. The profile highlights specialized tooling and passive backdoors that support persistent access to high-priority Middle Eastern networks, including government and telecommunications.

Mandiant reporting frames UNC1860 as a probable initial access provider with tooling that can enable persistent footholds and handoff-style operations. For Israeli and regional defenders, this means UNC1860 should be treated as an access-enablement and persistence risk even when another persona later conducts espionage, leakage, or destructive activity.

Defensive Focus

  • Public-facing edge systems.
  • IIS, SharePoint, Exchange, and externally reachable web applications.
  • Passive backdoors and webshell-like persistence.
  • Government and telecommunications networks.
  • Long-lived access that may be handed off to destructive or influence-operation teams.

Associated Families And Tools

Use the generated UNC1860 tool matrix and individual tool pages for behavior, hash/IOC status, sources, and defensive hunting notes:

Detection Ideas

  • New or modified files under web roots, SharePoint paths, IIS modules, and application upload directories.
  • Web server worker processes spawning shells, scripting engines, or archive tools.
  • Long-lived low-volume callbacks from edge servers.
  • New local or domain accounts created after public-facing application anomalies.
  • RDP, SMB, or WMI activity originating from web servers or DMZ hosts.
  • File integrity deviations on internet-facing systems outside approved deployment windows.

Analytic Caution

UNC1860 should not be used as a default attribution label for every Iran-linked webshell. Analysts SHOULD require multiple evidence lines: victimology, specialized tooling, infrastructure, passive backdoor behavior, and source-backed malware-family linkage.

Sources: SRC-MALPEDIA-UNC1860, SRC-MANDIANT-UNC1860.

Public Reports

Primary vendor reporting:

  • Mandiant / Google Cloud, "UNC1860 and the Temple of Oats: Iran's Footholds into Critical Networks" — September 2024. Primary public disclosure documenting full toolset (TEMPLEDOOR, TEMPLEPLAY, CRYPTOSLAY, PipeSnoop, STAYSHANTE, SASHEYAWAY, VIROGREEN, TEMPLEDROP, TEMPLELOCK), Middle East government and telecom victimology, and access-broker/handoff model. Source ID SRC-MANDIANT-UNC1860.
  • Malpedia, UNC1860 actor profile — Community-maintained actor taxonomy with associated malware family references and cross-vendor alias mapping. Source ID SRC-MALPEDIA-UNC1860.

Cross-references within repository: