STAYSHANTE
STAYSHANTE is a web shell used by the Iranian state-sponsored threat actor UNC1860, which Mandiant assesses is likely affiliated with Iran’s Ministry of Intelligence and Security (MOIS). It is deployed after initial access is obtained, typically following opportunistic exploitation of vulnerable internet-facing systems, and has been associated with intrusions targeting high-priority Middle Eastern networks, especially government and telecommunications organizations. Reporting also links STAYSHANTE indicators to activity affecting Israeli entities across sectors including managed service providers, local governments, and academia.
STAYSHANTE is part of UNC1860’s post-exploitation toolchain and is described as being installed under names masquerading as Windows server files or dependencies. It is controlled by the VIROGREEN custom framework, which is also used to exploit vulnerable SharePoint servers via CVE-2019-0604 and to manage post-exploitation payloads. UNC1860 commonly deploys STAYSHANTE alongside the SASHEYAWAY dropper/web-shell-related tooling, and these components are used to facilitate follow-on deployment of additional implants and passive backdoors such as TEMPLEDOOR and FACEFACE. Across the reporting, STAYSHANTE is consistently characterized as a web shell within UNC1860’s broader arsenal of more than 30 custom tools used to establish footholds and support persistent access.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Web shells like STAYSHANTE and SASHEYAWAY are frequently deployed after initial access is achieved.
Techniques & procedures
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Reconnaissance
1 technique
Reconnaissance
Persistence
1 technique
Persistence
Web shells like STAYSHANTE and SASHEYAWAY are frequently deployed after initial access is achieved. These shells enable further persistence by deploying full passive backdoors, such as TEMPLEDOOR and FACEFACE, which can execute commands, transfer files, and interact with system services.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell used by UNC1860 as an early-stage implant to establish an initial foothold and enable follow-on payload delivery.
Web shell used after exploitation of internet-facing servers to establish/maintain access; also referenced as being controlled by VIROGREEN.
A web shell deployed after initial access to maintain persistence and support follow-on deployment of fuller passive backdoors.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.