Cyber Avengers, also styled CyberAv3ngers, is an Iranian state-linked threat actor and persona cluster assessed to be associated with the Islamic Revolutionary Guard Corps (IRGC). The group has been active since at least 2020 and is widely associated with operations against Israeli organizations, especially critical infrastructure, while later reporting also places it among Iranian actors targeting U.S. operational technology and internet-connected infrastructure. Cyber Avengers is frequently described publicly as a hacktivist brand, but multiple assessments characterize it instead as an IRGC-linked operational group used for deniable or semi-deniable cyber activity within Iran’s broader proxy cyber ecosystem. The actor is strongly associated with targeting industrial control systems, operational technology, internet of things devices, and critical infrastructure sectors including water, power, industrial facilities, and aviation-related environments. Israeli water infrastructure has been a recurring focus, and the group has also been tied to activity involving programmable logic controllers, including Unitronics devices. Reporting further links the actor to disruptive and psychological operations that blend limited technical intrusion, opportunistic access, public claims, propaganda, and intimidation. Cyber Avengers has repeatedly amplified or exaggerated the impact of its operations, including claims around infrastructure disruption and industrial compromise, consistent with Iranian cyber-enabled influence tradecraft. Cyber Avengers has been connected to denial-of-service activity, attacks on industrial and internet-exposed devices, spoofing and mass messaging campaigns, and broader influence operations intended to intimidate targets and shape public perception. The actor has been described as conducting psychological operations and SMS spoofing campaigns during periods of regional escalation. Microsoft has associated the persona with Storm-784 and assessed that this cluster also operated the Soldiers of Solomon persona, with a focus on industrial control systems and IoT devices. The group has also been linked to compromises of webcams and to public leak-and-claim behavior intended to create the appearance of deeper operational impact than could be independently verified. Within Iran’s cyber structure, Cyber Avengers is commonly placed in the middle tier between top-level state-sponsored APT groups and looser ideological hacktivist coalitions. It is described as part of Tehran’s forward-defense model, in which proxies and branded personas provide plausible deniability while supporting retaliation, coercion, and strategic messaging. The actor has been named alongside other IRGC-linked operational groups such as Bavar373 and Cyber Fattah Team. Its activity has been especially prominent in the context of the Israel–Hamas war and subsequent regional escalation, where it has been used to frame attacks as retaliation and to support pro-Iranian narratives. The dominant pattern is retaliatory and politically driven targeting aligned with Iranian state interests rather than conventional criminal monetization. High-confidence reporting supports an espionage-oriented and disruptive state-linked mission focused on critical infrastructure access, intimidation, and influence rather than financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named Iranian-aligned hacktivist/proxy group expected to increase disruptive activity (e.g., DDoS, ransomware-as-cover) amid heightened Iran-West tensions; used as distraction/cover for more sophisticated operations.
Described as a coordinated (state-linked) hacktivist group involved in the June 2025 cyber escalation following Operation Rising Lion, conducting psychological operations, mass SMS spoofing, and OT-focused attacks impacting Unitronics PLC environments and water/industrial facilities, with spillover targeting including U.S. water utilities and financial infrastructure.
IRGC-linked operational group within Iran’s layered cyber proxy architecture.
Cyber Avengers is an Iranian state-backed threat actor, sanctioned and associated with the IRGC, known for targeting US networks, particularly operational technology (OT), IoT, water, and aviation systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.