CyberAv3ngers is an Iran-linked cyber threat actor widely associated with the Islamic Revolutionary Guard Corps Cyber-Electronic Command and also tracked under aliases including Av3ngers, Cyber Av2ngers, Shahid Kaveh Group, Storm-0784, Bauxite, and UNC5691. The group has operated as a faux-hacktivist or proxy-style persona that provides Tehran with deniability while conducting disruptive cyber operations aligned with Iranian geopolitical interests. CyberAv3ngers is best known for targeting operational technology and industrial control system environments, especially internet-exposed programmable logic controllers and related remote-access infrastructure. Confirmed and repeatedly reported victim sectors include water and wastewater utilities, energy, manufacturing, and government-related critical infrastructure. The actor has been linked to disruptive campaigns affecting small municipal water utilities in the United States and Ireland, and has also been associated with targeting infrastructure connected to Israel. The group’s tradecraft emphasizes operational disruption rather than stealthy long-term espionage or financially motivated ransomware. Reported techniques include reconnaissance of exposed OT assets, scanning for vulnerable internet-facing devices, abuse of default or weak credentials, use of legitimate engineering software to access and modify PLCs, manipulation of PLC project files, alteration of HMI and SCADA displays, and changes to controller configuration such as passwords and network settings that lock operators out of equipment. Public reporting also links the actor to persistence through remote-access tooling on compromised OT devices and to development or use of the IOCONTROL malware platform for OT and IoT environments. Campaigns associated with CyberAv3ngers have included disabling or disrupting automated controls, causing loss of operator view and control, and creating conditions that could affect safety or continuity of service. CyberAv3ngers has repeatedly focused on under-resourced municipal and critical infrastructure operators whose OT environments are directly reachable from the internet or exposed through poorly secured remote-access pathways. The actor’s historical activity includes compromise of Unitronics PLCs and later campaigns involving Rockwell Automation and Allen-Bradley equipment, with broader reporting also connecting Iranian-affiliated activity in the same ecosystem to Schneider Electric and Siemens PLC targeting. The group has publicly amplified its operations through online claims and propaganda messaging, including anti-Israel themes and threats against U.S. infrastructure, reinforcing its role as both a disruptive OT actor and an influence-oriented front for Iranian state cyber operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2021-22681 is a critical authentication bypass in Rockwell Automation's Logix controller ecosystem caused by an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Anyone who can obtain or intercept that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers.
On Monday, the U.S. Cybersecurity and Infrastructure Security Agency added the Unitronics bug to its Known Exploited Vulnerabilities catalog, assigning it CVE-2023-6448. The advisory warned that “Unitronics Vision Series PLCs and HMIs [Human Machine Interfaces] use default administrative passwords.” “An unauthenticated attacker with network access to a PLC or HMI can take administrative control of the system,” the agency said.
42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked cyber persona/group discussed as part of Tehran’s proxy or deniable cyber ecosystem, with prior targeting of operational technology and water/industrial control environments.
Publicly claimed responsibility for attacks on U.S. infrastructure in the context of ongoing activity targeting internet-exposed Rockwell Automation MicroLogix 1400 and 1100 PLCs. The underlying activity described involves remotely changing PLC IP addresses and enabling passwords on previously unprotected devices, locking out operators and causing loss of operator view.
Suspected of conducting disruptive cyberattacks against US water and wastewater utilities by targeting PLCs, with activity resembling earlier Iran-affiliated campaigns.
Referenced as an Iranian hacking group previously warned to be targeting internet-connected OT devices such as PLCs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.