Iranian APT UNC1860 Linked to MOIS Facilitates Cyber Intrusions in Middle East
The Ministry of Intelligence and Security (MOIS) is probably connected to an Iranian advanced persistent threat (APT) threat actor that is now serving as an initial access facilitator, granting remote access to target networks.
Google-owned Mandiant is following the activity cluster under the pseudonym UNC1860. According to Mandiant, this activity cluster is comparable to intrusion sets that are being tracked by Microsoft, Cisco Talos, and Check Point under the respective names Storm-0861 (previously DEV-0861), ShroudedSnooper, and Scarred Manticore.
UNC1860's collection of specialized tooling and passive backdoors is a key component, according to the company, that […] supports multiple objectives, including its potential role as a first access provider and its capacity to obtain co...


