logo

UNC1860 Attacks Targeting the Middle East (Campaign)

ID: c1a3ae58-df59-5178-8a9a-462196471e7d

STIX ID: report--c1a3ae58-df59-5178-8a9a-462196471e7d

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2024-09-20

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

UNC1860 is described as an Iranian state-sponsored threat actor (likely affiliated with MOIS) that targets government and telecommunications networks in the Middle East, using custom controllers and backdoors (TEMPLEPLAY/TEMPLEDOOR, VIROGREEN) along with stealthy implants (STAYSHANTE, SASHEYAWAY), encrypted C2, webshells and undocumented Windows kernel drivers to maintain long-term, covert access and to provide initial access for other malicious operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.