LiveActive security incident?Get immediate response
MITRE ATT&CK® Campaign

C0010: C0010

C0010 was a cyber espionage campaign conducted by UNC3890 that targeted Israeli shipping, government, aviation, energy, and healthcare organizations. Security researcher assess UNC3890 conducts operations in support of Iranian interests, and noted several limited technical connections to Iran, including PDB strings and Farsi language artifacts. C0010 began by at least late 2020, and was still ongoing as of mid-2022.[1]

EnterpriseC0010CampaignObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

C0010 matters because it describes a sustained espionage campaign against organizations in strategically important sectors: shipping, government, aviation, energy, and healthcare. For leaders, the decision value is not just the named campaign; it is the pattern: prepared infrastructure, drive-by access, tool transfer, custom backdoors, and browser credential harvesting. That combination can affect continuity, identity exposure, and incident response speed, especially where users browse from operational or high-trust environments.

Executive priority

Prioritize validation for organizations with similar sector exposure, regional relevance, or critical service dependencies. Executives should ask whether the security program can prove coverage for browser-based initial access, suspicious domain and web infrastructure use, inbound tool transfer, reverse-shell behavior, and credential harvesting from browsers. This campaign also supports audit and resilience discussions: do teams retain the endpoint, DNS, web proxy, and network evidence needed to reconstruct an intrusion that may involve custom malware rather than commodity indicators alone?

Technical view

ATT&CK provides no campaign-level detection text and no campaign-level platforms or tactics, so defenders should work from the related behaviors. C0010 is linked to Drive-by Compromise, Ingress Tool Transfer, adversary domain acquisition or hijacking, malware and tool staging, and two Windows-associated software entries: SUGARDUMP, a browser credential harvesting tool, and SUGARUSH, a custom backdoor that can establish a reverse shell over TCP to a hard-coded C2 address. SOC and IR teams should validate visibility across browser activity, endpoint process and file events, credential store access patterns, outbound network connections, DNS/domain reputation context, and file downloads from external infrastructure.

Likely telemetry

  • Endpoint process, file creation, and module/script execution telemetry on user workstations and servers where available
  • Browser activity and web proxy logs, including redirects, downloads, and unusual access to newly observed or suspicious domains
  • DNS query logs and domain registration/reputation enrichment for acquired, hijacked, or staged domains
  • Network egress telemetry for reverse shell-like TCP sessions and command-and-control patterns
  • File download and transfer records that could indicate ingress tool transfer from external infrastructure

Detection direction

  • Because MITRE provides no official detection guidance for this campaign, avoid relying on campaign name matching; validate behavior-based detections for the related techniques.
  • Tune detections for drive-by compromise around abnormal browser child processes, unexpected downloads, redirects, and post-browsing execution, while accounting for legitimate software update and web application behavior.
  • Monitor for ingress tool transfer by correlating external downloads, newly written executables or scripts, and subsequent execution or network egress.
  • Review outbound TCP connections for unusual long-lived sessions, rare destinations, or hard-coded C2-like behavior, especially when associated with uncommon binaries.
  • Hunt for browser credential harvesting behaviors on Windows systems, including unusual access to browser credential stores by non-browser processes.

Mitigation priorities

  • Start with evidence readiness: ensure endpoint, DNS, web proxy, and network egress logs are collected and retained long enough to support investigation.
  • Reduce browser-based exposure through timely browser and plugin patching, hardened browser configuration, web filtering, and controls around downloads and script execution.
  • Limit credential exposure by reducing browser-stored secrets where appropriate, enforcing strong identity controls, and monitoring for account misuse after suspected endpoint compromise.
  • Constrain egress with allowlisting or policy-based controls where feasible, and alert on unusual outbound TCP connections to rare or newly observed destinations.
  • Apply application control and least privilege to reduce execution of downloaded tools and custom malware.
Additional notes and limits

The object is a campaign entry, not a technique, and MITRE does not provide campaign-level detection text. The strongest defensive guidance comes from the official description and relationships to SUGARDUMP, SUGARUSH, Drive-by Compromise, Ingress Tool Transfer, and resource-development techniques involving domains, malware, tools, and staged infrastructure. Attribution and targeting statements are limited to the supplied ATT&CK description and the cited Mandiant reporting.

No campaign-level platforms, tactics, or official detection guidance are specified. The campaign was reported as ongoing as of mid-2022, but the supplied fields do not support claims of current activity. Local relevance depends on sector, geography, technology stack, logging maturity, and whether related behaviors appear in the environment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

C0010

C0010 was a cyber espionage campaign conducted by UNC3890 that targeted Israeli shipping, government, aviation, energy, and healthcare organizations. Security researcher assess UNC3890 conducts operations in support of Iranian interests, and noted several limited technical connections to Iran, including PDB strings and Farsi language artifacts. C0010 began by at least late 2020, and was still ongoing as of mid-2022.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

9 rows
DomainIDNameRelationship / procedure
EnterpriseT1584.001DomainsSub-technique

During C0010, UNC3890 actors likely compromised the domain of a legitimate Israeli shipping company.[1]

EnterpriseT1608.001Upload MalwareSub-technique

For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system.[1]

EnterpriseT1189Drive-by Compromise

During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021.[1]

EnterpriseT1608.004Drive-by TargetSub-technique

For C0010, the threat actors compromised the login page of a legitimate Israeli shipping company and likely established a watering hole that collected visitor information.[1]

EnterpriseT1587.001MalwareSub-technique

For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP.[1]

EnterpriseT1583.001DomainsSub-technique

For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer.[1]

EnterpriseT1105Ingress Tool Transfer

During C0010, UNC3890 actors downloaded tools and malware onto a compromised host.[1]

EnterpriseT1608.002Upload ToolSub-technique

For C0010, UNC3890 actors staged tools on their infrastructure to download directly onto a compromised system.[1]

EnterpriseT1588.002ToolSub-technique

For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2.[1]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S1042: SUGARDUMP

SUGARDUMP is a proprietary browser credential harvesting tool that was used by UNC3890 during the C0010 campaign. The first known SUGARDUMP version was used since at least early 2021, a second SMTP C2 version was used from late 2021-early 2022, and a third HTTP C2 variant was used since at least April 2022.[1]

Windows
MalwareEnterprise

S1049: SUGARUSH

SUGARUSH is a small custom backdoor that can establish a reverse shell over TCP to a hard coded C2 address. SUGARUSH was first identified during analysis of UNC3890's C0010 campaign targeting Israeli companies, which began in late 2020.[1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
3ada8a2ce610e571...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle3ada8a2ce610…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  2. [2]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  3. [3]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  4. [4]
    mitre-attackC0010
    Open source URL
  5. [5]
    mitre-attackC0010
    Open source URL
  6. [6]
    mitre-attackC0010
    Open source URL
  7. [7]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  8. [8]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  9. [9]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  10. [10]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  11. [11]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  12. [12]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  13. [13]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  14. [14]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  15. [15]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  16. [16]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  17. [17]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  18. [18]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  19. [19]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  20. [20]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  21. [21]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  22. [22]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  23. [23]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  24. [24]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  25. [25]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  26. [26]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  27. [27]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.