logo

Meet UNC1860: Iran's Low-Key Access Broker for State Hackers

ID: f8349051-bc50-5ff0-917d-88845da25f48

STIX ID: report--f8349051-bc50-5ff0-917d-88845da25f48

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-09-24

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

This report describes UNC1860, an Iran-linked initial-access APT that scans and compromises public-facing assets across government, telecommunications, media, academia, and critical infrastructure, then sells or hands off access to other Iranian threat groups; it documents roughly 30 custom tools (web shells, droppers, backdoors and passive HTTPS listeners using undocumented HTTP.sys calls), named IoCs (e.g., Stayshante, Sasheyaway), and operational tradecraft that emphasize stealth and inbound-only command activation to avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.