VIROGREEN is a custom GUI-operated post-exploitation framework associated with the Iranian state-sponsored threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security. It has been used in intrusions targeting high-priority networks in the Middle East, particularly government and telecommunications organizations, and appears designed in part to facilitate handoff of access to other operators.
The framework is used to exploit vulnerable Microsoft SharePoint servers via CVE-2019-0604 and to manage compromised systems after initial access. Reported functionality includes scanning for and exploiting SharePoint exposure, controlling payloads and compatible backdoors, executing commands, and transferring files. VIROGREEN has also been linked to control of the STAYSHANTE web shell and management of additional payloads such as BASEWALK, making it part of a broader intrusion chain in which UNC1860 opportunistically compromises internet-facing servers and then deploys web shells, droppers, and passive implants.
Operationally, VIROGREEN fits UNC1860’s broader tradecraft of stealthy long-term access, support for follow-on operations, and enablement of remote access into victim environments. The surrounding toolset includes passive backdoors and loaders that reduce reliance on conventional outbound command-and-control traffic, complicating network detection. In this ecosystem, VIROGREEN serves as an operator-facing controller for exploitation and post-compromise tasking rather than as a standalone destructive payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VIROGREEN is a custom framework used to exploit vulnerable SharePoint servers with CVE-2019-0604. The framework provides post-exploitation capabilities including scanning for and exploiting CVE-2019-0604 | VIROGREEN is a custom framework used to exploit vulnerable SharePoint servers with CVE-2019-0604.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VIROGREEN is a custom framework used to exploit vulnerable SharePoint servers with CVE-2019-0604.
TEMPLEPLAY and VIROGREEN Controllers: These GUI-operated malware controllers allow UNC1860 or third-party actors to manage compromised systems easily.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
VIROGREEN is a custom framework used to exploit vulnerable SharePoint servers with CVE-2019-0604... UNC1860 gains initial access to victim environments in an opportunistic manner via the exploitation of vulnerable internet-facing servers leading to web shell deployment.
TEMPLEPLAY and VIROGREEN... were used to provide a team outside of UNC1860 remote access to victim networks... the ability to remotely access infected networks via RDP... It appears that it is primarily intended to facilitate an RDP connection with the target server.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware framework used by Iranian threat actors for espionage and persistence.
Custom framework/controller used to exploit SharePoint (CVE-2019-0604) and manage post-exploitation tooling including web shells/backdoors and command/file operations.
A GUI-operated malware controller used to manage compromised systems, including command execution, file transfer, and HTTP proxy functionality to facilitate RDP in restricted environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.