CyberAv3ngers is an Iranian threat actor affiliated with the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC), active since at least 2020. It conducts politically motivated, anti-Israel operations against industrial control systems, operational technology, and civilian critical infrastructure. It is also tracked as Bauxite, Storm-0784, and UNC5691, with aliases including Av3ngers, Cyber Avengers, CyberAveng3rs, and Shahid Kaveh Group. Microsoft tracks CyberAv3ngers and the associated Soldiers of Solomon group together as Storm-0784. The group targets internet-accessible programmable logic controllers and human-machine interfaces, particularly Israeli-manufactured equipment deployed in Israel and abroad. Confirmed targeting includes the United States and United Kingdom, with water and wastewater utilities prominent among its victims. Its tradecraft includes scanning for exposed controllers, using default or weak credentials, altering controller configurations and ladder logic, changing remote-access credentials, and replacing HMI displays with anti-Israel messages. These operations can impair operator visibility, disrupt equipment, and force facilities into manual operation. Between November 2023 and January 2024, its Unitronics campaigns compromised at least 75 controllers, including 34 in the U.S. water and wastewater sector. The November 2023 compromise of the Municipal Water Authority of Aliquippa disrupted a pressure-regulation pump, although the utility reported no impact on drinking-water safety. Private-sector industrial equipment, including brewery controls, was also affected. CyberAv3ngers has deployed IOCONTROL, also known as OrpaCrab, a modular malware family designed for Linux-based OT and IoT devices, including routers, controllers, HMIs, and firewalls. The group publicizes operations through attack claims and imagery of compromised systems, combining operational disruption with propaganda. In February 2024, the U.S. Treasury sanctioned six IRGC-CEC officials in connection with the group's activities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE-2021-22681 is a critical authentication bypass in Rockwell Automation's Logix controller ecosystem caused by an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Anyone who can obtain or intercept that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers.
On Monday, the U.S. Cybersecurity and Infrastructure Security Agency added the Unitronics bug to its Known Exploited Vulnerabilities catalog, assigning it CVE-2023-6448. The advisory warned that “Unitronics Vision Series PLCs and HMIs [Human Machine Interfaces] use default administrative passwords.” “An unauthenticated attacker with network access to a PLC or HMI can take administrative control of the system,” the agency said.
On April 8, the CyberAv3ngers released a technical video claiming successful unauthorized access to a series of internet-exposed Barix endpoints. A forensic reconstruction of the video's logs reveals an exploitation path centered on CVE-2024-41700, a high-severity information exposure vulnerability affecting Barix SIP client firmware.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Iranian IRGC-linked threat group scrutinized in connection with U.S. water-sector intrusions. It has targeted internet-exposed industrial controllers, initially abusing default passwords on Israeli-made water-utility controllers, later deploying IOCONTROL malware, and more recently exploiting an authentication-bypass flaw in Rockwell Automation Logix PLCs.
An Iranian-linked group presented as connected to APT Iran and associated with infrastructure threats and purported industrial-control-system compromise activity.
An IRGC-affiliated activity group linked to attacks on civilian and critical infrastructure, including campaigns against exposed Unitronics Vision Series PLCs in the United States.
Iranian IRGC-affiliated activity group conducting disruptive operations against internet-exposed Unitronics Vision Series PLCs, particularly in U.S. water and wastewater systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.