0attributed CVEs
14ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
—years active
About this actor
[C0010](https://attack.mitre.org/campaigns/C0010) was a cyber espionage campaign conducted by UNC3890 that targeted Israeli shipping, government, aviation, energy, and healthcare organizations. Security researcher assess UNC3890 conducts operations in support of Iranian interests, and noted several limited technical connections to Iran, including PDB strings and Farsi language artifacts. [C0010](https://attack.mitre.org/campaigns/C0010) began by at least late 2020, and was still ongoing as of mid-2022.(Citation: Mandiant UNC3890 Aug 2022)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 14 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1105Ingress Tool Transfer ↗T1189Drive-by Compromise ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1584Compromise Infrastructure ↗T1584.001Domains ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗T1608.002Upload Tool ↗T1608.004Drive-by Target ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
AC-4 | 2 / 14 | 14% |
CA-7 | 2 / 14 | 14% |
CM-2 | 2 / 14 | 14% |
CM-6 | 2 / 14 | 14% |
SC-7 | 2 / 14 | 14% |
SI-3 | 2 / 14 | 14% |
SI-4 | 2 / 14 | 14% |
AC-6 | 1 / 14 | 7% |
CM-7 | 1 / 14 | 7% |
CM-8 | 1 / 14 | 7% |
SA-22 | 1 / 14 | 7% |
SC-18 | 1 / 14 | 7% |
SC-2 | 1 / 14 | 7% |
SC-29 | 1 / 14 | 7% |
SC-3 | 1 / 14 | 7% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Mustard Tempest 0.33
- CostaRicto 0.32
- C0021 0.29
- Operation Sharpshooter 0.24
- IndigoZebra 0.24