UNC3890
Repository Navigation
- Actor workbench: UNC3890
- TTP-to-detection matrix: all mapped techniques
- Surface and capability routes: None currently mapped.
- Detection status: dashboard
- Hunt workflow: hunt workflow
- ATT&CK mappings: T1189 Drive-by Compromise (M2)
- Mapped detections: None currently mapped.
- Mapped hunts: None currently mapped.
- IOC reference sources:
SRC-MANDIANT-UNC3890Punycode domains; malware references; infrastructure - Tool detail pages:
SUGARUSH / SUGARDUMP - Tool matrix: all actor-linked tools (1 mapped tool row(s))
- Evidence records:
EVD-025/CLM-UNC3890-001 - Imported research intakes: APT39 Arid Viper UNC3890 Cyber Toufan Deep Research Intake (Medium, Needs source validation)
- Intel update candidates: None in current feed pull.
- Source IDs in structured data:
SRC-MANDIANT-UNC3890,SRC-SECWEEK-UNC3890
Background
UNC3890 is an Iran-linked threat cluster documented by Mandiant in September 2022. The group targets Israeli organizations across a distinctive sector set: shipping, aviation, healthcare, government, and energy — sectors that collectively intersect with Israel's national logistics, medical infrastructure, and civil aviation systems. Mandiant assessed an Iran nexus without resolving the sponsor to a specific Iranian agency based on reviewed reporting.
The group's technical approach combines watering-hole attacks and targeted phishing. Drive-by compromise sites were set up to deliver credential-harvesting landing pages, and the group operated dedicated infrastructure impersonating login portals for Israeli organizations. Two custom malware families are associated with the cluster: SUGARUSH — a small backdoor connecting to C2 over standard protocols — and SUGARDUMP — a browser credential stealer targeting Chrome, Firefox, Edge, and Opera credential stores. The combination of credential theft and web-based initial access suggests a reconnaissance and intelligence collection mandate with credentials as the primary commodity.
The maritime and aviation targeting is particularly relevant in an Israeli government context. Israel's ports, civil aviation authority, and logistics chains intersect significantly with civilian government operations, and credential theft from these sectors can provide intelligence on goods movement, traveler manifests, and operational scheduling useful to an adversary with strategic interests in disrupting Israeli trade or pre-positioning for escalation scenarios.
As of primary-source review, public reporting on UNC3890 is largely confined to the 2022 Mandiant disclosure and associated SecurityWeek coverage. The cluster should be treated as possibly evolved or operating under different vendor designations in more recent reporting; analysts should monitor for SUGARUSH/SUGARDUMP hash or behavioral matches in relevant sector environments.
Assessed sponsor: Suspected Iran-linked activity cluster in public reporting.
Relevance
UNC3890 is relevant because public reporting summarized by SecurityWeek describes targeting of Israeli shipping and other sectors including government, energy, aviation, and healthcare.
Defensive Focus
- Watering-hole and lure infrastructure.
- Credential collection.
- Supplier and sector-adjacent compromise.
- Maritime and aviation exposure connected to public-sector operations.
Detection Ideas
- Browser downloads from sector-themed lure domains.
- Credential submission to non-government domains after phishing reports.
- New external authentication sources for maritime, aviation, or logistics users.
Sources: SRC-MANDIANT-UNC3890, SRC-SECWEEK-UNC3890.
Public Reports
Own ecosystem:
- Deep Research Intake: APT39, Arid Viper, UNC3890, Cyber Toufan — Internal repository synthesis. Medium-priority, requires source validation.
Primary vendor reporting:
- Mandiant / Google Cloud, "UNC3890: Iranian Threat Actor Targets Israeli Shipping, Healthcare, and Government" — September 2022. Primary public disclosure documenting victimology (shipping, aviation, healthcare, government, energy), watering-hole infrastructure, SUGARUSH backdoor, and SUGARDUMP credential stealer. Source ID
SRC-MANDIANT-UNC3890. - SecurityWeek, coverage of the Mandiant UNC3890 report — Secondary reporting providing additional context on Israeli sector targeting and Mandiant's attribution methodology. Source ID
SRC-SECWEEK-UNC3890.