UNC3890: The Iranian Nexus Behind Attacks on Israeli Shipping and Healthcare
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Malware,RAT,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Mandiant's August 2022 report introduces UNC3890, a suspected Iranian-nexus threat actor tracked since late 2020, targeting Israeli shipping, government, energy, aviation, and healthcare organizations. Attribution indicators include Farsi language artifacts in malware code ("KHODA" meaning god, "yaal" meaning horse's mane), focused targeting of Israeli entities consistent with other Iranian actors, and a shared PDB path with UNC2448 (an IRGC-linked group). UNC3890 employs two custom tools: SUGARUSH — a small TCP reverse-shell backdoor that creates a "Service1" Windows service, connects to a hardcoded C2 on port 4585, and executes received CMD commands — and SUGARDUMP, a Chromium browser credential harvester with three observed versions: an early version (stores credentials locally), an SMTP version (exfiltrates via Yahoo/Yandex/Gmail using john.macperson2021 accounts, uses a robotic dolls commercial as lure), and an HTTP version (AES-CBC encrypted exfiltration to C2, uses a fake LexisNexis job offer lure). Initial access vectors include a watering hole on a legitimate Israeli shipping company's login page (sending victim data to xn--lirkedin-vkb[.]com), credential harvesting via lookalike domains (pfizerpoll[.]com, office365update[.]live, rnfacebook[.]com), spearphishing links, and potentially trusted relationships. Public tools used include Metasploit, UNICORN (Magic Unicorn), and NorthStar C2. IOCs include 8 C2 IPs, 10 domains (including a Punycode LinkedIn lookalike), 4 attacker email addresses, and 23 file hashes.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | LexisNexis LexisNexis is a part of the RELX corporation that sells data analytics products and various databases that are accessed through online portals, including portals for computer-assisted legal research, newspaper search, and consumer information. LexisNexis has been targeted by UNC3890 with abusive purposes. | Verified |
| Case | LinkedIn LinkedIn is a business and employment-focused social media platform that works through websites and mobile apps. It was launched on May 5, 2003. It is now owned by Microsoft. LinkedIn has been targeted by UNC3890 with abusive purposes. | Verified |
| Case | Pfizer Pfizer Inc. is an American multinational pharmaceutical and biotechnology corporation headquartered at The Spiral in Manhattan, New York City. The company was established in 1849 in New York by two German entrepreneurs, Charles Pfizer and his cousin Charles F. Erhart. Pfizer has been targeted by UNC3890 with abusive purposes. | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Medical | Verified |
| Sector | Transportation | Verified |
| Sector | Utilities | Verified |
| Region | Israel | Verified |
Extracted IOCs
- aspiremovecentraldays[.]net
- celebritylife[.]news
- fileupload[.]shop
- kedin[.]com
- naturaldolls[.]store
- office365update[.]live
- pfizerpoll[.]com
- rnfacebook[.]com
- xn--lirkedin-vkb[.]com
- xxx-doll[.]com
- john.macperson2021@gmail[.]com
- john.macperson2021@yahoo[.]com
- john.macperson2021@yandex[.]com
- john.macperson@protonmail[.]com
- 084ad50044d6650f9ed314e99351a608
- 08dc5c2af21ecee6f2b25ebdd02a9079
- 2a09c5d85667334d9accbd0e06ae9418
- 2fe42c52826787e24ea81c17303484f9
- 37bdb9ea33b2fe621587c887f6fb2989
- 3b2a719ffb12a291acbfe9056daf52a7
- 3f045ebb014d859a4e7d15a4cf827957
- 532f5c8a85b706ccc317b9d4158014bf
- 639f83fa4265ddbb43e85b763fe3dbac
- 6dbd612bbc7986cf8beb9984b473330a
- 9c8788e7ae87ae4f46bfe5ba7b7aa938
- a7a2d6a533b913bc50d14e91bcf6c716
- ae0a16b6feddd53d1d52ff50d85a42d5
- c5116a9818dcd48b8e9fb1ddf022df29
- d47bbec805c00a549ab364d20a884519
- d528e96271e791fab5818c01d4bc139f
- d5671df2af6478ac108e92ba596d5557
- d8fb3b6f5681cf5eec2b89be9b632b05
- e125ed072fc4529687d98cf4c62e283e
- f362a2d9194a09eaca7d2fa04d89e1e5
- f538cb2e584116a586a50d607d517cfd
- f97c0f19e84c79e9423b4420531f5a25
- fcc09a4262b9ca899ba08150e287caa9
- 104[.]237.155.129
- 128[.]199.6.246
- 143[.]110.155.195
- 144[.]202.123.248
- 146[.]185.219.88
- 159[.]223.164.185
- 161[.]35.123.176
- 185[.]170.215.170
Tip: 45 related IOCs (8 IP, 10 domain, 0 URL, 4 email, 23 file hash) to this threat have been found.
FAQs
Frequently Asked Questions About UNC3890's Campaign Against Israeli Organizations
UNC3890, a suspected Iranian-nexus threat actor, conducted a sustained espionage campaign targeting Israeli organizations in the shipping, government, energy, aviation, and healthcare sectors from at least late 2020 through mid-2022. The group used a combination of watering holes, credential-harvesting lookalike websites, fake job offer lures, and social engineering videos to deliver two custom tools — SUGARUSH (a TCP backdoor) and SUGARDUMP (a browser credential stealer) — alongside publicly available frameworks. Mandiant documented and published the campaign in August 2022.
The campaign is attributed to UNC3890, a suspected Iranian-nexus threat actor. Mandiant's attribution is based on multiple converging indicators: the group's exclusive focus on Israeli organizations aligns with other Iranian APT targeting patterns; Farsi language artifacts were found embedded in SUGARDUMP malware code (the word "KHODA" meaning god in an AES encryption key, and a project named "yaal" — horse's mane in Farsi); and a shared PDB file path was identified linking UNC3890 to UNC2448, a group independently assessed as linked to the Iranian Revolutionary Guard Corps (IRGC). At the time of publication, Mandiant had not definitively confirmed formal affiliation with a specific Iranian government body.
The primary goal was intelligence collection — establishing persistent access to Israeli organizations to harvest credentials and gather strategic intelligence. SUGARDUMP's sole purpose is stealing browser credentials from Chrome, Opera, Edge, and Firefox, giving the group access to victim accounts and services far beyond the initial footpoint. SUGARUSH provides a persistent reverse shell for command execution and deeper network access. The group's particular interest in the Israeli shipping sector and its monitoring of naval cargo movements suggests intelligence collection tied to the ongoing maritime conflict between Iran and Israel in this period.
The campaign targeted Israeli organizations across multiple sectors — shipping, government, energy, aviation, and healthcare — all active from at least late 2020 through mid-2022. The group also targeted individuals through fake LinkedIn, Office 365, Facebook, and Pfizer credential-harvesting pages, suggesting individual employees at these organizations were directly targeted for credential theft. Artifacts uploaded to VirusTotal from Israel confirm the geographic focus. The group's particular emphasis on the shipping sector reflects the ongoing Iranian-Israeli maritime shadow conflict during this period.
Israeli shipping companies are of direct strategic interest to Iran given the maritime shadow war between the two countries — Iran has targeted Israeli-linked cargo ships for sabotage, and intelligence on shipping routes, cargo manifests, and naval movements would be operationally valuable. Israeli government and energy organizations hold diplomatic and infrastructure intelligence. Healthcare organizations hold sensitive personal data on Israeli citizens. The group's multi-sector focus suggests a broad intelligence collection mandate rather than a single operational objective, consistent with state-sponsored espionage priorities.
UNC3890 used several initial access methods in parallel. A watering hole was planted on a legitimate Israeli shipping company's login page — when employees visited it, their credentials were silently sent to a Punycode LinkedIn lookalike domain (xn--lirkedin-vkb.com). Spearphishing emails carried fake job offers (including a LexisNexis lure) and a link to a video commercial for robotic dolls that triggered a malicious download. Credential-harvesting pages mimicked LinkedIn, Office 365, Facebook, and Pfizer portals. Once on a victim system, SUGARUSH established a reverse TCP shell to the attacker's C2 on port 4585, while SUGARDUMP collected saved credentials from all major browsers and exfiltrated them either via webmail (Yahoo/Yandex accounts) or AES-encrypted HTTP POST to the C2 server.
SUGARDUMP evolved across three documented versions. The first version (early 2021) extracted browser credentials and stored them locally without any exfiltration capability — likely used for manual collection during active access. The second SMTP version (late 2021) added automated exfiltration via webmail using Yahoo, Yandex, and Gmail accounts under the john.macperson2021 alias, and used a robotic dolls commercial video as a delivery lure. The third HTTP version (April 2022) replaced the webmail exfiltration with AES-CBC encrypted HTTP POST to the attacker's C2 server, added a fake LexisNexis job offer lure, and embedded the Farsi word "KHODA" in the AES encryption key — a Farsi cultural artifact left by the developer. Each version reflects a more operationally mature capability with better OPSEC.
Block all 8 documented C2 IPs and 10 domains — particularly the Punycode LinkedIn lookalike xn--lirkedin-vkb.com and doll-themed infrastructure (naturaldolls.store, xxx-doll.com). Alert on SUGARUSH indicators: creation of a Windows service named "Service1" and outbound TCP connections on port 4585 from non-standard processes. Monitor SUGARDUMP indicators: browser credential database file access (Chrome Login Data, Edge User Data, Opera) by non-browser processes, and outbound SMTP connections to smtp.yandex.com or smtp.mail.yahoo.com on port 587 from endpoints. Alert on scheduled tasks named "MicrosoftEdgeCrashRepoeterTaskMachineUA" — note the deliberate typo, which is a SUGARDUMP persistence artifact. Train staff on social engineering lures specifically designed for Israeli users: fake job offers from recognizable companies, video download prompts, and login pages for LinkedIn, Office 365, and Facebook hosted on unfamiliar domains.