SPARKLOAD is a passive backdoor associated with the Iranian state-linked threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security and active against government and telecommunications networks across the Middle East. It is one of several stealth-oriented implants used by the group after initial compromise, alongside TEMPLEDOOR and FACEFACE, and is delivered through the SASHEYAWAY dropper as part of UNC1860’s post-compromise tooling.
UNC1860 commonly gains access by exploiting vulnerable internet-facing servers and deploying web shells or droppers, after which passive implants such as SPARKLOAD are installed to maintain covert long-term access. This tradecraft emphasizes listener-based malware that avoids initiating outbound command-and-control traffic, complicating network detection and supporting handoff of access to other operators within the Iranian cyber ecosystem. SPARKLOAD is therefore best understood as part of a broader intrusion set focused on stealthy persistence and post-exploitation access in strategically important regional targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...execution of implants, such as TEMPLEDOOR, FACEFACE, and SPARKLOAD...
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A follow-on implant referenced as a backdoor (and likely loader functionality) used by UNC1860 to expand capability after initial access.
Implant executed from within the SASHEYAWAY dropper as part of the UNC1860 toolchain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.