CSIDB logo
Threat actor

UNC215

Attribution profile

Type
Sensationalist
Location
Iran
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-30 18:33
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

UNC215 is a threat actor that has been publicly referenced under this alias and is associated with Iran-based operations. The actor came to attention in April 2020 when it claimed responsibility for gaining unauthorized access to the .np domain administered by Mercantile Communications Pvt Ltd in Nepal. According to reporting from Nepal’s Cyber Bureau, the group exploited personal data obtained from customers of Foodmandu, Vianet Communications and Prabhu Remit to compromise the domain registrar’s infrastructure. The actor’s online presence included a Twitter account using the handle ‘Satan’, which police suspected to be a collective account for the hackers. No further details about the actor’s size, internal structure, or funding sources are available in the open source material.

The actor’s targeting appears to focus on Nepal’s digital infrastructure, particularly entities that manage domain registration and related services. The intrusion into the .np domain demonstrates an interest in compromising critical naming services that could affect a broad range of downstream users. Beyond the registrar, the actor publicly threatened to infiltrate systems belonging to the Nepal Electricity Authority, Daraz Nepal, Kantipur Publication, the Nepal National Museum, district agriculture offices under the Department of Agriculture, and the National Nepal Library. These statements indicate a willingness to extend activity into government utilities, e‑commerce, media, cultural institutions and public administration. The reported method of initial access involved leveraging leaked or stolen customer information from three specific service providers, suggesting a reliance on credential harvesting or data breach exploitation rather than custom malware. No specific malware families, exploit kits or tooling suites are described in the source.

The most notable operation attributed to UNC215 is the April 2020 compromise of the .np domain server, during which the actor asserted that the majority of data on the server was publicly accessible via whois queries. Mercantile Communications responded by suspending new domain registrations as a precaution and noted that other .np services appeared unaffected at the time. The actor’s subsequent threats to target additional Nepalese organizations represent a follow‑on campaign that was disclosed in the same reporting cycle but not confirmed as having been executed. These incidents constitute the only publicly documented activities linked to UNC215 at this time.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB