Iran-linked APT group UNC1860 is operating as an initial access facilitator that provides remote access to Middle Eastern Networks.
UNC1860 specializes in using customized tools and passive backdoors to gain persistent access to high-profile networks in the government and telecommunications sectors across the Middle East.
The group shares tactics with other Iran-linked threat groups and may support state-sponsored hackers in performing lateral movement.
UNC1860's arsenal includes a wide range of passive tools and backdoors supporting initial access, lateral movement, and data gathering.