UNC3890
Named by MandiantSuspected state sponsor: Islamic Republic of IranUNC3890 is Mandiant's designation for a suspected Iranian threat actor active since at least late 2020, focused on intelligence collection targeting Israeli government, shipping, energy, aviation, and healthcare organizations. The group uses watering hole attacks — including compromising the login page of a legitimate Israeli shipping company — alongside social engineering lures featuring fake job offers, fake Office 365 and LinkedIn login pages, and a video commercial for an AI-based robotic doll to harvest credentials and deliver malware. Its custom toolset includes SUGARUSH, a small backdoor providing remote command execution, and SUGARDUMP, a browser credential stealer that exfiltrates stolen credentials via Gmail, Yahoo, and Yandex accounts. Mandiant assessed with moderate confidence that UNC3890 is Iran-linked based on Farsi language artifacts in the malware code, victim overlap with other Iranian actors, and targeting patterns consistent with Iranian state intelligence priorities — particularly Iran's documented interest in monitoring and potentially disrupting Israeli maritime operations.
Targeted Regions
IsraelIsrael
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.