Actors Insights|Latest update24/07/2026

UNC788

Named by MandiantSuspected state sponsor: Islamic Republic of Iran

UNC788 is Mandiant's unclassified threat cluster designation for an Iranian-linked group focused on mobile surveillance operations targeting Iranian and diaspora individuals. The group is known for operating fake Android applications designed to harvest sensitive data from targeted individuals, consistent with Iran's domestic surveillance mission. UNC788 activity includes credential theft, contact harvesting, and location tracking of opposition figures and Iranian minority communities. Mandiant's UNC designation indicates attribution confidence had not yet reached the threshold for formal classification into a named group at time of reporting. MITRE ATT&CK also tracks this cluster under the identifier G1029.

First Seen:Jan 2022
Last Seen:Aug 2024
Indexed Reports:0
Public IOCs:0
Cluster: UnclassifiedMitre: UNC788Misp: APT42
also known as:
UNC788 (Mandiant)CALANQUEAPT42 (Mandiant)G1029 (Mitre)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.