BASEWALK is a backdoor associated with the Iranian state-linked threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security and active primarily against government and telecommunications organizations in the Middle East. The malware appears in UNC1860 intrusion chains that begin with exploitation of vulnerable internet-facing systems, especially SharePoint servers vulnerable to CVE-2019-0604, followed by deployment of web shells, droppers, and passive implants to establish durable access.
BASEWALK is managed through the VIROGREEN framework, a custom operator console used for exploitation and post-exploitation tasking. VIROGREEN has been used to control STAYSHANTE and the BASEWALK backdoor, execute commands, transfer files, and coordinate follow-on activity after initial compromise. In this ecosystem, UNC1860 commonly combines web-shell access with stealth-oriented passive implants and backdoors intended to minimize conventional command-and-control visibility and support long-term persistence or handoff of access to other operators.
The malware is part of a broader UNC1860 toolset that supports initial access enablement, post-compromise operations, and persistent footholds. UNC1860 has also been observed using compromised environments as staging points for scanning and exploitation of additional regional targets, and its tooling overlaps operationally with other MOIS-linked activity clusters, including APT34. BASEWALK is therefore best understood as one component of a larger Iranian intrusion framework designed to support covert access, operator tasking, and sustained espionage-oriented operations on Windows-based enterprise systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The framework provides post-exploitation capabilities including scanning for and exploiting CVE-2019-0604; controlling post-exploitation payloads, backdoors (including the STAYSHANTE web shell and the BASEWALK backdoor) and tasking.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...it controls STAYSHANTE, along with a backdoor referred to as BASEWALK.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.