STAYSHANTE is a web shell associated with the Iranian state-sponsored threat cluster UNC1860, which is widely assessed to be linked to Iran’s Ministry of Intelligence and Security. It is deployed on compromised servers after initial access, typically as part of intrusion chains targeting government and telecommunications organizations in the Middle East, and has also been linked to broader operations affecting regional entities including Israeli organizations during 2024 wiper-related activity. UNC1860 is assessed to use STAYSHANTE as part of its role as an initial access and persistence provider, enabling follow-on operations and possible handoff to other MOIS-affiliated operators.
STAYSHANTE is controlled through the VIROGREEN framework and is used in post-compromise operations on internet-facing servers, including environments exposed through vulnerable SharePoint systems. It is commonly installed under names intended to resemble legitimate Windows server components or dependencies, supporting defense evasion and blending into the host environment. In UNC1860 intrusion chains, STAYSHANTE appears alongside related tooling such as the SASHEYAWAY dropper and passive backdoors including TEMPLEDOOR, FACEFACE, and SPARKLOAD, forming part of a layered access architecture designed for stealthy long-term footholds.
The malware’s operational role is consistent with server-side persistence and post-exploitation support rather than standalone destructive action. UNC1860 commonly exploits vulnerable public-facing servers to gain entry, deploys web shells such as STAYSHANTE, and then establishes more covert passive implants that reduce reliance on conventional outbound command-and-control traffic. This tradecraft has made the group notable for stealth, operational flexibility, and support of espionage-oriented access into high-priority regional networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Web shells like STAYSHANTE and SASHEYAWAY are frequently deployed after initial access is achieved.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
VIROGREEN is a custom framework used to exploit vulnerable SharePoint servers with CVE-2019-0604... UNC1860 gains initial access to victim environments in an opportunistic manner via the exploitation of vulnerable internet-facing servers leading to web shell deployment.
UNC1860 web shells and droppers, such as STAYSHANTE and SASHEYAWAY, deployed and placed on compromised servers by the group after gaining initial access have the potential to be used in hand-off operations... technical indicators included the unique STAYSHANTE web shell and the SASHEYAWAY dropper.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell used by UNC1860 as an early-stage implant to establish an initial foothold and enable follow-on payload delivery.
Web shell used after exploitation of internet-facing servers to establish/maintain access; also referenced as being controlled by VIROGREEN.
A web shell deployed after initial access to maintain persistence and support follow-on deployment of fuller passive backdoors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.