Actors Insights|Latest update24/07/2026

UNC3890

Named by MandiantSuspected state sponsor: Islamic Republic of Iran

UNC3890 is Mandiant's designation for a suspected Iranian threat actor active since at least late 2020, focused on intelligence collection targeting Israeli government, shipping, energy, aviation, and healthcare organizations. The group uses watering hole attacks — including compromising the login page of a legitimate Israeli shipping company — alongside social engineering lures featuring fake job offers, fake Office 365 and LinkedIn login pages, and a video commercial for an AI-based robotic doll to harvest credentials and deliver malware. Its custom toolset includes SUGARUSH, a small backdoor providing remote command execution, and SUGARDUMP, a browser credential stealer that exfiltrates stolen credentials via Gmail, Yahoo, and Yandex accounts. Mandiant assessed with moderate confidence that UNC3890 is Iran-linked based on Farsi language artifacts in the malware code, victim overlap with other Iranian actors, and targeting patterns consistent with Iranian state intelligence priorities — particularly Iran's documented interest in monitoring and potentially disrupting Israeli maritime operations.

First Seen:Nov 2020
Last Seen:Aug 2022
Indexed Reports:1
Public IOCs:45
Cluster: UnclassifiedMisp: UNC3890
also known as:
UNC3890 (Mandiant)

Targeted Regions

Israel
IL
Israel
Israel
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Nov 2020 ~ Aug 2022
Jan 2020Sep 2026

Targeted Sectors

Government Agencies and ServicesMedicalTransportationUtilities

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.