CyberAv3ngers is an Iran-linked threat actor widely associated with the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). The group is also tracked under aliases including Bauxite, Hydro Kitten, Shahid Kaveh Group, Soldiers of Solomon, Storm-0784, and UNC5691. It has been publicly characterized as a disruptive, propaganda-oriented actor focused on operational technology and industrial control systems, particularly internet-exposed programmable logic controllers, HMIs, SCADA environments, and adjacent IoT infrastructure. CyberAv3ngers is best known for targeting civilian critical infrastructure, especially water and wastewater utilities, fuel management systems, and other industrial environments in the United States and Israel. Reported activity includes compromises of Unitronics controllers at U.S. water facilities, disruptive operations affecting water services in Ireland, and campaigns against fuel-management and payment-terminal infrastructure tied to gas stations in Israel and the United States. The group has also been linked to broader targeting of government, manufacturing, and energy-related environments. Observed tradecraft emphasizes opportunistic exploitation of weakly secured OT assets rather than highly sophisticated initial access. The actor has repeatedly been associated with abuse of default or weak credentials, direct access to internet-exposed PLCs and HMIs, use of vendor engineering and configuration software, manipulation of PLC project files and controller settings, and disruption through password changes, IP reconfiguration, and forced loss of operator visibility or control. Public reporting also links the group to custom OT malware known as IOCONTROL, a modular Linux-based tool designed for IoT and OT devices that supports persistence, encrypted configuration, secure command-and-control, remote command execution, self-deletion, and scanning. IOCONTROL has been assessed as capable of affecting routers, PLCs, HMIs, firewalls, IP cameras, and fuel-management systems. The actor’s operations align primarily with espionage-adjacent pre-positioning and disruptive coercive activity in support of Iranian state interests rather than financially motivated crime. Its campaigns have frequently coincided with geopolitical tensions involving Iran and have often targeted infrastructure associated with the United States, Israel, and allied interests. CyberAv3ngers has also used public claims and messaging to amplify psychological impact and project capability, reinforcing its role as an Iran-aligned disruptive actor operating against critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2021-22681 is a critical authentication bypass in Rockwell Automation's Logix controller ecosystem caused by an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Anyone who can obtain or intercept that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers.
On Monday, the U.S. Cybersecurity and Infrastructure Security Agency added the Unitronics bug to its Known Exploited Vulnerabilities catalog, assigning it CVE-2023-6448. The advisory warned that “Unitronics Vision Series PLCs and HMIs [Human Machine Interfaces] use default administrative passwords.” “An unauthenticated attacker with network access to a PLC or HMI can take administrative control of the system,” the agency said.
44 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Accused of targeting industrial control systems, including water utilities; discussed here in connection with suspected attacks on Minnesota water systems, though officials say they do not believe the Minnesota attacks were orchestrated by CyberAv3ngers.
IRGC-affiliated actor associated here with attacks on water utilities, including exploitation of internet-exposed PLCs using default credentials and disruption/defacement of HMI operations.
Suspected of conducting opportunistic, propagandistic attacks against US water infrastructure by targeting Internet-exposed PLCs, modifying passwords, changing IP addresses, locking out operators, and causing operational disruption intended to stoke fear rather than extort or cause permanent damage.
Iran-linked cyber persona/group discussed as part of Tehran’s proxy or deniable cyber ecosystem, with prior targeting of operational technology and water/industrial control environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.