SASHEYAWAY is a malware component associated with the Iranian state-sponsored threat cluster UNC1860, which is assessed to be linked to Iran’s Ministry of Intelligence and Security. It is used in intrusions targeting high-priority networks in the Middle East, particularly government and telecommunications organizations, and has also been observed in activity linked to broader disruptive operations affecting Israeli entities.
SASHEYAWAY is consistently described as a dropper deployed after initial access has been obtained on compromised servers. UNC1860 commonly gains that access by exploiting vulnerable internet-facing systems and then installing server-side tooling such as web shells and droppers. SASHEYAWAY is used in this post-compromise phase to execute embedded passive implants, including TEMPLEDOOR, FACEFACE, and SPARKLOAD. Its role in the intrusion chain is to facilitate the transition from initial foothold to more durable and stealthy access.
A defining characteristic of the UNC1860 toolset is the use of passive backdoors that avoid traditional outbound command-and-control patterns, complicating network-based detection. SASHEYAWAY supports this tradecraft by serving as a launcher for such implants rather than acting as a conventional interactive backdoor itself. Reporting also notes that it has exhibited a low detection rate, which aligns with UNC1860’s broader emphasis on stealth, long-term persistence, and handoff of access to other operators.
SASHEYAWAY has been referenced alongside the STAYSHANTE web shell as part of UNC1860’s server-side access toolkit. It is attributed to the same operational ecosystem that includes controllers such as TEMPLEPLAY and VIROGREEN and additional passive implants and loaders used to maintain covert access in victim environments. The malware is associated with Windows-focused follow-on payload execution, though it is deployed on compromised servers as part of intrusion activity against enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Web shells like STAYSHANTE and SASHEYAWAY are frequently deployed after initial access is achieved.
ShroudedSnooper built a sprawling toolkit of passive backdoors and web shells — including the LionTail framework, TEMPLEDOOR, SASHEYAWAY, and a repurposed Windows kernel driver derived from Iranian antivirus software — designed to sustain long-term, low-visibility access.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
VIROGREEN is a custom framework used to exploit vulnerable SharePoint servers with CVE-2019-0604... UNC1860 gains initial access to victim environments in an opportunistic manner via the exploitation of vulnerable internet-facing servers leading to web shell deployment.
UNC1860 web shells and droppers, such as STAYSHANTE and SASHEYAWAY, deployed and placed on compromised servers by the group after gaining initial access have the potential to be used in hand-off operations... technical indicators included the unique STAYSHANTE web shell and the SASHEYAWAY dropper.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ShroudedSnooper tool used to maintain stealthy persistent access in telecom and government networks.
A dropper/loader used by UNC1860 to deploy additional backdoors after initial access is obtained.
Dropper used to execute embedded implants (TEMPLEDOOR, FACEFACE, SPARKLOAD).
A web shell used post-compromise for persistence and staging of additional passive backdoors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.