Meet UNC1860: Iran's Low-Key Access Broker for State Hackers
ID: f8349051-bc50-5ff0-917d-88845da25f48
STIX ID: report--f8349051-bc50-5ff0-917d-88845da25f48
Feed Name: Dark Reading
This report describes UNC1860, an Iran-linked initial-access APT that scans and compromises public-facing assets across government, telecommunications, media, academia, and critical infrastructure, then sells or hands off access to other Iranian threat groups; it documents roughly 30 custom tools (web shells, droppers, backdoors and passive HTTPS listeners using undocumented HTTP.sys calls), named IoCs (e.g., Stayshante, Sasheyaway), and operational tradecraft that emphasize stealth and inbound-only command activation to avoid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
