UNC788

MITRE ATT&CK: G1029 View on attack.mitre.org

Aliases: UNC788

First seen
2020-06-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:30:47

Targeted industries: government-and-public-sector defense-and-aerospace energy-and-utilities

Targeted regions: country_code:sa country_code:ae country_code:iq

Context

UNC788 is a group of hackers from Iran that has targeted people in the Middle East.

Malware & tools used

  • Phishing (attack-pattern)
  • HilalRAT (malware)

Reports & references

  • about.fb.com — Meta Quarterly Adversarial Threat Report Q1 2022 (report)
  • MITRE ATT&CK — G1029 (report)

External references