TEMPLEDROP is a Windows passive backdoor associated with the Iranian state-linked threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security. It has been used in intrusions targeting high-priority organizations in the Middle East, particularly government and telecommunications networks, and appears to be reserved for higher-value victims as part of UNC1860’s long-term persistence toolkit.
A defining characteristic of TEMPLEDROP is its repurposing of a legitimate Windows file system filter driver from the Iranian antivirus product Sheed AV. UNC1860 uses this driver to protect TEMPLEDROP itself and other deployed malware from modification, strengthening stealth and resilience on compromised systems. This behavior reflects the actor’s broader emphasis on passive implants, kernel-level tradecraft, and defense evasion designed to reduce visibility to endpoint and network monitoring.
Within UNC1860 operations, TEMPLEDROP fits into a broader post-compromise workflow in which the actor commonly gains initial access by exploiting vulnerable internet-facing servers, deploys web shells and droppers, and then installs more covert implants for sustained access. UNC1860 is widely assessed to function in part as an initial access provider for other Iranian operators, and its tooling is designed to maintain footholds that can later support follow-on espionage, lateral movement, and broader network operations. TEMPLEDROP’s file-protection role and passive backdoor design make it particularly suited for stealthy persistence in strategically important environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This driver is used in TEMPLEDROP, a passive backdoor that protects its own files and other malware it deploys, preventing modification and enhancing its evasion capabilities.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Both passive implants TOFUDRV and TOFULOAD leverage undocumented Input/Output Control commands for communication... using them promises lower detection rates and possibilities akin to filtering drivers, which act as middlemen allowing for the inspection, modification, or blocking of network traffic before it reaches the device or application, as well as assets like file system objects and registry entries.
UNC1860 relies on custom-made passive backdoors like TOFULOAD and WINTAPIX, which leverage undocumented Input/Output Control (IOCTL) commands for communication, bypassing standard detection mechanisms used by EDR systems. These implants operate without initiating outbound traffic, making them difficult to detect through traditional network monitoring tools.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A main-stage, more sophisticated backdoor used by UNC1860 for high-value targets.
Repurposed file system filter driver (from Sheed AV) used to protect deployed files from modification (defense evasion/self-protection).
A passive backdoor used with a repurposed Sheed AV kernel driver for stealthy persistence and self-protection, preventing modification of its files and other deployed malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.