Mandiant reported that UNC1860, an Iranian state-sponsored threat actor likely tied to the Ministry of Intelligence and Security (MOIS), maintained long-term access in government and telecommunications networks across the Middle East using a broad toolset of passive backdoors, web shells, droppers, and custom controllers. The group deployed malware including TEMPLEDOOR, FACEFACE, SPARKLOAD, TEMPLEDROP, TOFUDRV, and TOFULOAD, alongside controllers such as TEMPLEPLAY and VIROGREEN, to preserve stealth and evade detection. Cisco Talos separately described a related pattern of telecom targeting in the region by ShroudedSnooper, which used the novel implants HTTPSnoop and PipeSnoop to intercept specially crafted HTTP(S) requests and named-pipe traffic while masquerading as Palo Alto Cortex XDR components.
The activity fits a broader pattern of Iranian cyber operations spanning espionage, access brokering, and destructive attacks. Mandiant said UNC1860 used compromised environments to scan and exploit additional regional targets, including entities in Saudi Arabia and Qatar, and identified overlaps with APT34 and other MOIS-linked clusters. Check Point and Microsoft have also documented Iranian operations tied to telecom surveillance, attacks on the Albanian government, destructive activity in Israel, and cyber-enabled support operations aligned with Hamas, reinforcing assessments that Tehran-linked actors are using covert implants, telecom access, and regional footholds to support both intelligence collection and disruptive campaigns.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Mandiant reported that UNC1860 is a persistent Iranian state-sponsored actor likely affiliated with MOIS and active against government and telecommunications networks across the Middle East. The report also said UNC1860 likely acts as an initial access provider and linked its tooling to the March 2024 wiper activity targeting Israeli organizations.
Check Point published research on Void Manticore's destructive operations in Israel, adding public reporting on the March 2024 Israel-focused activity.
In March 2024, the Israeli National Cyber Directorate was alerted to wiper activity targeting Israeli entities across managed service providers, local governments, and academia. Mandiant later linked technical indicators from this activity, including STAYSHANTE and SASHEYAWAY, to UNC1860 tooling.
Check Point published research on Scarred Manticore operations spanning Albania to the Middle East, adding public reporting on the actor's regional surveillance activity.
Cisco Talos publicly identified the new intrusion set ShroudedSnooper and disclosed the HTTPSnoop and PipeSnoop implants used against Middle Eastern telecom providers. Talos also shared findings with Microsoft and Palo Alto Networks.
Talos reported that the HTTPSnoop implant was first crafted on April 17, 2023, with later variants appearing on April 19 and April 29. The malware listens for specific HTTP(S) URLs and executes received shellcode.
Microsoft investigated Iranian cyberattacks against the Albanian government, an operation later tied to the broader actor cluster discussed in subsequent reporting on Scarred Manticore and related activity.
Cisco Talos said the ShroudedSnooper intrusion set targeted telecommunications providers in the Middle East with the HTTPSnoop and PipeSnoop implants. Talos said the activity likely occurred between August 2022 and April 2023 based on the masqueraded software versioning.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 71 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
cloud.google.com
Open sourceresearch.checkpoint.com
Open sourceresearch.checkpoint.com
Open sourceblog.talosintelligence.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.