C0010

C0010

Campaign, Dec 2020 to Aug 2022.View on attack.mitre.org

About this campaign

C0010 was a cyber espionage campaign conducted by UNC3890 that targeted Israeli shipping, government, aviation, energy, and healthcare organizations. Security researcher assess UNC3890 conducts operations in support of Iranian interests, and noted several limited technical connections to Iran, including PDB strings and Farsi language artifacts. C0010 began by at least late 2020, and was still ongoing as of mid-2022.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1105
Ingress Tool Transfer

During C0010, UNC3890 actors downloaded tools and malware onto a compromised host.

T1189
Drive-by Compromise

During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021.

T1583.001
Domains

For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer.

T1584.001
Domains

During C0010, UNC3890 actors likely compromised the domain of a legitimate Israeli shipping company.

T1587.001
Malware

For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP.

T1588.002
Tool

For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2.

T1608.001
Upload Malware

For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system.

T1608.002
Upload Tool

For C0010, UNC3890 actors staged tools on their infrastructure to download directly onto a compromised system.

T1608.004
Drive-by Target

For C0010, the threat actors compromised the login page of a legitimate Israeli shipping company and likely established a watering hole that collected visitor information.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software2

References1

  1. Mandiant UNC3890 Aug 2022 Open source
    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.