TEMPLELOCK is a .NET-based defense-evasion utility associated with the Iranian state-linked threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security. It has been observed as part of UNC1860 intrusion sets targeting government and telecommunications organizations in the Middle East, including use alongside foothold tooling such as ROTPIPE and passive implants such as TEMPLEDROP.
Its primary documented function is interference with Windows logging by terminating the Windows Event Log service, a behavior that can reduce host-based visibility and hinder forensic reconstruction of attacker activity. This places TEMPLELOCK within a broader UNC1860 tradecraft pattern centered on stealth, long-term persistence, and support for follow-on operations by other operators. UNC1860 commonly gains access through exploitation of vulnerable internet-facing systems and deployment of web shells and droppers, after which specialized utilities and passive backdoors are used to maintain covert access and facilitate post-compromise activity.
TEMPLELOCK is best understood as a supporting utility rather than a standalone access platform. Within UNC1860 operations it complements passive implants, loaders, controllers, and kernel-driver-based tooling designed to evade detection, preserve access, and enable sustained espionage or network operations in strategically important environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TEMPLELOCK, a .NET defense evasion utility that's capable of killing the Windows Event Log service
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.