TUNNELBOI is a custom network tunneling and controller utility associated with the Iranian state-linked threat cluster UNC1860, which is assessed to be affiliated with the Ministry of Intelligence and Security. It is used in intrusions targeting high-priority networks, particularly government and telecommunications organizations in the Middle East, as part of broader operations focused on establishing and maintaining covert access.
The malware is designed to establish connectivity with remote hosts and facilitate operator access inside compromised environments. Reported functionality includes managing remote desktop connections and, in some reporting, managing web shells present on the network. Its role is consistent with UNC1860’s broader tradecraft of enabling follow-on access and post-compromise operations for other operators, including support for movement within victim environments and access to otherwise less reachable systems.
TUNNELBOI appears within an ecosystem of UNC1860 tooling that emphasizes stealthy persistence, passive implants, and operator-controlled access mechanisms rather than noisy commodity command-and-control patterns. Development overlap has been noted with other UNC1860 tools through shared obfuscation or encryption components. The malware is part of a larger intrusion set that includes web shells, droppers, passive backdoors, loaders, and defense-evasion tooling used after exploitation of internet-facing systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TUNNELBOI, a network controller capable of establishing a connection with a remote host and managing RDP connections
1 distinct technique documented for this family, organized by ATT&CK tactic.
TEMPLEPLAY and VIROGREEN... were used to provide a team outside of UNC1860 remote access to victim networks... the ability to remotely access infected networks via RDP... It appears that it is primarily intended to facilitate an RDP connection with the target server.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.