UNC788
MITRE ATT&CK: G1029 View on attack.mitre.org
Aliases: UNC788
- First seen
- 2020-06-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:30:47
Targeted industries: government-and-public-sector defense-and-aerospace energy-and-utilities
Targeted regions: country_code:sa country_code:ae country_code:iq
Context
UNC788 is a group of hackers from Iran that has targeted people in the Middle East.
Malware & tools used
- Phishing (attack-pattern)
- HilalRAT (malware)
Reports & references
- about.fb.com — Meta Quarterly Adversarial Threat Report Q1 2022 (report)
- MITRE ATT&CK — G1029 (report)