UNC1860
- First seen
- 2018-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:17:59
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:sa country_code:ae country_code:iq country_code:bh
Context
UNC1860 is a persistent and opportunistic Iranian state-sponsored threat actor that is likely affiliated with Iran’s Ministry of Intelligence and Security (MOIS). A key feature of UNC1860 is its collection of specialized tooling and passive backdoors that Mandiant believes supports several objectives, including its role as a probable initial access provider and its ability to gain persistent access to high-priority networks, such as those in the government and telecommunications space throughout the Middle East.
Reports & references
- cloud.google.com — Unc1860 Iran Middle Eastern Networks (report)