TEMPLEPLAY is a custom .NET-based GUI-operated malware controller associated with the Iranian state-sponsored threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security. It is used as a controller for the TEMPLEDOOR passive backdoor and appears designed to provide remote access into compromised environments, including for operators outside the core UNC1860 team. The malware supports remote command execution, file upload and download, and HTTP proxying through infected hosts. This proxying capability can be used to facilitate RDP access to otherwise inaccessible internal systems, effectively turning compromised hosts into middleboxes for follow-on operations.
TEMPLEPLAY is part of a broader UNC1860 intrusion ecosystem focused on persistent, stealthy access to high-priority networks in the Middle East, especially government and telecommunications organizations. UNC1860 commonly gains initial access by exploiting vulnerable internet-facing servers and deploying web shells or droppers, after which passive implants and controllers such as TEMPLEPLAY are used to maintain access and enable post-compromise activity. Reporting indicates the controller was used in operations where access may have been handed off to other MOIS-affiliated actors, consistent with UNC1860’s assessed role as an initial access provider and facilitator for subsequent intrusion activity.
The controller is notable for fitting into UNC1860’s broader tradecraft centered on passive implants, operational handoff, and detection evasion. It has been observed alongside other UNC1860 tooling including VIROGREEN, STAYSHANTE, SASHEYAWAY, and TEMPLEDOOR. Its role is primarily post-compromise access enablement and remote operations management rather than initial delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mandiant identified two custom, GUI-operated malware controllers tracked as TEMPLEPLAY and VIROGREEN that we assess were used to provide a team outside of UNC1860 remote access to victim networks.
TEMPLEPLAY and VIROGREEN Controllers: These GUI-operated malware controllers allow UNC1860 or third-party actors to manage compromised systems easily.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
TEMPLEPLAY and VIROGREEN... were used to provide a team outside of UNC1860 remote access to victim networks... the ability to remotely access infected networks via RDP... It appears that it is primarily intended to facilitate an RDP connection with the target server.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware framework used by Iranian threat actors for espionage, persistence, and lateral movement.
GUI-operated .NET-based controller used to manage the TEMPLEDOOR backdoor, supporting command execution, file transfer, and proxying connections.
A GUI-operated malware controller used to manage compromised systems, supporting command execution, file transfer, and proxying infected systems as middleboxes for RDP access.
Templeplay is a backdoor tool used by Iranian state-sponsored threat actor UNC1860 to maintain persistent access to targeted networks, enabling espionage and further attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.