FACEFACE is a passive backdoor associated with the Iranian state-sponsored threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security and active against government and telecommunications networks across the Middle East. It is part of a broader UNC1860 toolchain built to establish stealthy, long-term access after exploitation of internet-facing systems and deployment of intermediary web shells or droppers such as SASHEYAWAY and STAYSHANTE.
FACEFACE is described as a more substantial follow-on implant that can be deployed from UNC1860 staging components. Its documented functionality includes remote command execution, file transfer, and interaction with system services, placing it among the actor’s main post-compromise access mechanisms. UNC1860’s operational model emphasizes passive implants that minimize or avoid conventional outbound command-and-control traffic, a tradecraft pattern intended to reduce network-detection opportunities and support covert persistence in high-value environments.
FACEFACE appears in intrusion chains where UNC1860 first gains access by exploiting vulnerable public-facing servers, then installs web shells or droppers, and subsequently deploys passive backdoors for durable access and possible handoff to other operators. Reporting on UNC1860 indicates overlap and possible collaboration with other MOIS-linked groups, including APT34, and suggests the actor may function as an initial access provider within the Iranian cyber ecosystem. FACEFACE therefore fits into a broader espionage-oriented intrusion framework focused on persistence, stealth, and enabling downstream operations in strategically important regional networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These shells enable further persistence by deploying full passive backdoors, such as TEMPLEDOOR and FACEFACE, which can execute commands, transfer files, and interact with system services.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Web shells like STAYSHANTE and SASHEYAWAY are frequently deployed after initial access is achieved. These shells enable further persistence by deploying full passive backdoors, such as TEMPLEDOOR and FACEFACE, which can execute commands, transfer files, and interact with system services.
UNC1860 relies on custom-made passive backdoors like TOFULOAD and WINTAPIX, which leverage undocumented Input/Output Control (IOCTL) commands for communication, bypassing standard detection mechanisms used by EDR systems. These implants operate without initiating outbound traffic, making them difficult to detect through traditional network monitoring tools.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A follow-on backdoor used by UNC1860 to deepen access/persistence beyond initial implants.
Implant executed from within the SASHEYAWAY dropper as part of the UNC1860 toolchain.
A full passive backdoor used for persistence, command execution, file transfer, and service interaction on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.