UNC3890 is a threat cluster linked with high confidence to Iranian cyber activity and associated with espionage-oriented operations targeting Israeli organizations, particularly in the shipping and logistics sector. The actor is known for operating watering-hole campaigns in which a legitimate Israeli shipping company login page was likely compromised and used to profile visitors and potentially enable follow-on compromise. Activity attributed to UNC3890 was active until at least November 2021. UNC3890 has used strategic web compromise and impersonation infrastructure as core tradecraft. The group established lookalike domains masquerading as major online services and brands, and used attacker-controlled infrastructure to stage malware and tools for direct download onto compromised systems. Reported tooling includes publicly available offensive frameworks such as Metasploit, Unicorn, and NorthStar C2, alongside bespoke malware families including SUGARUSH and SUGARDUMP. Observed behavior indicates a focus on initial access, reconnaissance, payload staging, and post-compromise tool transfer. The watering-hole activity collected visitor information from targeted users, and the actor subsequently downloaded tools and malware onto compromised hosts. The combination of spoofed domains, strategic web compromise, staged payload delivery, and custom malware is consistent with a targeted intrusion set supporting Iranian intelligence collection priorities. UNC3890 has also been discussed in connection with Tortoiseshell, also known as TA456 or Imperial Kitten, though that specific attribution is lower confidence than the broader Iranian nexus.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stages malware on actor-controlled infrastructure for direct download onto compromised systems.
Uses public exploitation and C2 frameworks in operations.
Uses unique malware families SUGARUSH and SUGARDUMP.
Downloads tools and malware onto compromised hosts during the referenced activity cluster/campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.