TEMPLEDOOR is a passive Windows backdoor associated with the Iranian state-sponsored threat cluster UNC1860, which is assessed to be affiliated with Iran’s Ministry of Intelligence and Security. It has been used in intrusions targeting high-priority networks in the Middle East, particularly government and telecommunications organizations, as part of UNC1860’s broader strategy of establishing stealthy, long-term access and in some cases enabling follow-on operations by other Iranian operators.
TEMPLEDOOR is typically deployed after initial compromise through UNC1860 web shells and droppers, notably STAYSHANTE and SASHEYAWAY, following exploitation of vulnerable internet-facing systems. It is part of a family of passive implants and backdoors that minimize reliance on traditional outbound command-and-control traffic, complicating network-based detection. A dedicated .NET controller known as TEMPLEPLAY is used to operate TEMPLEDOOR and provides capabilities including remote command execution, file upload and download, and HTTP proxying through compromised hosts. This proxying can facilitate access to otherwise unreachable internal systems, including support for remote desktop connectivity through infected middleboxes.
Observed functionality attributed to TEMPLEDOOR includes executing commands, transferring files, and interacting with system services. Its role within UNC1860 tradecraft is consistent with post-compromise persistence and covert remote access rather than smash-and-grab collection. TEMPLEDOOR has been deployed alongside other UNC1860 implants such as FACEFACE and SPARKLOAD, and forms part of a larger ecosystem of passive tooling that includes loaders, kernel-assisted implants, and defense-evasion utilities. The malware reflects UNC1860’s emphasis on stealth, operational handoff, and durable footholds inside strategically important victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These shells enable further persistence by deploying full passive backdoors, such as TEMPLEDOOR and FACEFACE, which can execute commands, transfer files, and interact with system services.
ShroudedSnooper built a sprawling toolkit of passive backdoors and web shells — including the LionTail framework, TEMPLEDOOR, SASHEYAWAY, and a repurposed Windows kernel driver derived from Iranian antivirus software — designed to sustain long-term, low-visibility access.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Web shells like STAYSHANTE and SASHEYAWAY are frequently deployed after initial access is achieved. These shells enable further persistence by deploying full passive backdoors, such as TEMPLEDOOR and FACEFACE, which can execute commands, transfer files, and interact with system services.
TEMPLEPLAY and VIROGREEN... were used to provide a team outside of UNC1860 remote access to victim networks... the ability to remotely access infected networks via RDP... It appears that it is primarily intended to facilitate an RDP connection with the target server.
The Http Proxy Tab allows a remote machine infected with TEMPLEDOOR to be used as a middlebox that forwards data to a chosen target server.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Passive backdoor used by ShroudedSnooper for long-term low-visibility access.
Web shell/backdoor used by Iranian threat actors for persistence and remote access after exploiting VPN and firewall vulnerabilities.
A more substantial follow-on backdoor downloaded/deployed by UNC1860 after initial foothold is established.
Implant/backdoor executed via SASHEYAWAY; controlled by TEMPLEPLAY and supports command execution, file transfer, and proxying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.