XORO is a rolling XOR encryption module used within the UNC1860 malware ecosystem. It functions as a reusable obfuscation component rather than a standalone payload family, and has been observed embedded across multiple UNC1860-associated utilities including TANKSHELL, TUNNELBOI, and the TEMPLEPLAY controller. UNC1860 is an Iranian state-sponsored threat actor widely assessed to be affiliated with the Ministry of Intelligence and Security and known for persistent intrusions against government and telecommunications networks in the Middle East. Within that toolchain, XORO supports concealment of data or communications used by other malware components and reflects the actor’s broader pattern of custom encoding, encryption, and defense-evasion tradecraft. Available information supports classifying XORO as an auxiliary encryption/obfuscation module used by Windows-based UNC1860 tooling, not as an independently deployed malware family with its own delivery vector or victim-facing functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For example, XORO, a rolling encryption module (MD5: 57cd8e220465aa8030755d4009d0117c), is used in several utilities such as TANKSHELL and TEMPLEPLAY.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.