Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
🇮🇷 IR7 malware familiesExploits CVEs in the wild

CyberAv3ngers

Also known asBAUXITECyber Av3ngersCyberAv3ngersshahid_kaveh_groupSoldiers of Solomanstorm_0784unc5691

CyberAv3ngers is an Iranian threat actor active since at least 2023 and assessed in the provided content to operate under or in coordination with Iran’s Islamic Revolutionary Guard Corps (IRGC), specifically the IRGC Cyber-Electronic Command. The group is also tracked as Bauxite, Storm-0784, UNC5691, cyber_av3ngers, Shahid Kaveh Group, and Soldiers of Solomon; the content also notes Hydro Kitten as an additional tracking name. Multiple sources in the content describe the group as using hacktivist branding for deniability while conducting state-linked operations. The group is focused on industrial control systems and internet-connected OT/IoT devices, especially programmable logic controllers used in water, wastewater, energy, and municipal environments. The content states that CyberAv3ngers compromised at least 75 Israeli-made Unitronics Vision Series PLC devices across U.S. and allied critical infrastructure beginning in November 2023, including attacks on U.S. water facilities such as the Municipal Water Authority of Aliquippa, Pennsylvania. In those operations, the group used default factory credentials on internet-exposed Unitronics devices and defaced HMIs with anti-Israel messaging, including 'You have been hacked, down with Israel' and statements that equipment 'made in Israel' was a legal target. The content also links the group to a water-sector disruption in County Mayo, Ireland involving Unitronics equipment. The content further describes CyberAv3ngers as highly focused on accessing ICS and IoT devices and as the IRGC Cyber-Electronic Command’s industrial-control-system arm. It notes later activity resembling or attributed to the group against internet-exposed Rockwell Automation and Allen-Bradley PLC environments in U.S. critical infrastructure, including abuse of FactoryTalk software and manipulation of HMI/SCADA-related data. The group is described as part of a broader Iranian OT targeting pattern affecting water, energy, and government facilities. The content also records earlier hacktivist-style claims by CyberAv3ngers during the October 2023 Israel-Hamas conflict, including claimed attacks against Israel’s Noga Independent System Operator, the Dorad power station, Mekorot, and ORPAK. One analysis in the content concluded that the Dorad claim reused older leaked material rather than demonstrating new access. Overall, the provided material consistently portrays CyberAv3ngers as an IRGC-linked, OT-focused threat actor that evolved from public hacktivist messaging into confirmed state-linked operations against civilian critical infrastructure.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Utilities
  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics44 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595
Active Scanning
TA0001
Initial Access
4 techniques
T1078×6
Valid Accounts
T1078.001×4
Default Accounts
T1190×8
Exploit Public-Facing Application
T1195
Supply Chain Compromise
T1566
Phishing
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1106×2
Native API
TA0003
Persistence
2 techniques
T1037
Boot or Logon Initialization Scripts
T1078×6
Valid Accounts
T1078.001×4
Default Accounts
TA0004
Privilege Escalation
3 techniques
T1037
Boot or Logon Initialization Scripts
T1068
Exploitation for Privilege Escalation
T1078×6
Valid Accounts
T1078.001×4
Default Accounts
TA0005
Stealth
3 techniques
T1070
Indicator Removal
T1078×6
Valid Accounts
T1078.001×4
Default Accounts
T1140
Deobfuscate/Decode Files or Information
TA0006
Credential Access
1 technique
T1110×2
Brute Force
TA0007
Discovery
3 techniques
T1046×6
Network Service Discovery
T1082
System Information Discovery
T1654
Log Enumeration
TA0008
Lateral Movement
2 techniques
T1021×6
Remote Services
T1021.004
SSH
T1210
Exploitation of Remote Services
TA0011
Command and Control
4 techniques
T1071×4
Application Layer Protocol
T1071.004×3
DNS
T1071.005
Publish/Subscribe Protocols
T1105×2
Ingress Tool Transfer
T1571
Non-Standard Port
T1573
Encrypted Channel
TA0010
Exfiltration
1 technique
T1537
Transfer Data to Cloud Account
TA0040
Impact
9 techniques
T1485×5
Data Destruction
T1486
Data Encrypted for Impact
T1489
Service Stop
T1490
Inhibit System Recovery
T1491×7
Defacement
T1491.001×2
Internal Defacement
T1498×6
Network Denial of Service
T1499×5
Endpoint Denial of Service
T1531×2
Account Access Removal
T1565
Data Manipulation
T1565.001×2
Stored Data Manipulation
IOCS

Observables

13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping38

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal7

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs2

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables13

Domains, IPs, and hashes tied to this actor, refreshed continuously.