CyberAv3ngers is an Iran-linked, IRGC Cyber-Electronic Command-affiliated threat actor focused on operational technology, industrial control systems, and internet-exposed IoT devices. It is also tracked as Bauxite, Hydro Kitten, Shahid Kaveh Group, Soldiers of Solomon, Storm-0784, and UNC5691. The group has targeted U.S. and Israeli critical-infrastructure environments, particularly water utilities, fuel-management systems, and electric infrastructure; UK-based internet-accessible PLC and HMI systems have also been within its documented targeting scope. In 2023, CyberAv3ngers compromised exposed Unitronics PLC and HMI devices at U.S. water utilities using default credentials, including activity that caused HMI defacement and required affected operations to use manual control. The group has also claimed attacks against Israeli electric infrastructure, although individual public claims have not always been substantiated. CyberAv3ngers has been linked to IOCONTROL, a modular Linux-focused IoT/OT malware family capable of persistence, encrypted configuration handling, MQTT command-and-control, DNS-over-HTTPS resolution, system reconnaissance, arbitrary command execution, port scanning, and self-removal. IOCONTROL activity affected fuel-management infrastructure and other device classes including PLCs, HMIs, routers, firewalls, and cameras. The actor's known tradecraft emphasizes scanning for exposed industrial devices, abusing default or weak credentials, use of legitimate vendor engineering and configuration software, configuration and project-file manipulation, and disruption of operator monitoring or control. Iranian-affiliated PLC-targeting campaigns observed in 2026 were assessed as similar to prior CyberAv3ngers activity, but public evidence did not conclusively attribute those later campaigns or the July 2026 UK generator incident to CyberAv3ngers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2021-22681 is a critical authentication bypass in Rockwell Automation's Logix controller ecosystem caused by an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Anyone who can obtain or intercept that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers.
On Monday, the U.S. Cybersecurity and Infrastructure Security Agency added the Unitronics bug to its Known Exploited Vulnerabilities catalog, assigning it CVE-2023-6448. The advisory warned that “Unitronics Vision Series PLCs and HMIs [Human Machine Interfaces] use default administrative passwords.” “An unauthenticated attacker with network access to a PLC or HMI can take administrative control of the system,” the agency said.
44 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only for comparison with a separate, earlier PLC-targeting campaign against Rockwell systems; it is not attributed to the activity described in this advisory.
Iran-affiliated group documented targeting internet-accessible PLC and HMI systems, including devices in the UK; mentioned here as contextual comparison rather than confirmed actor behind the incident.
Suspected of conducting disruptive attacks against exposed PLCs in critical infrastructure environments, including water utilities in the U.S. and potentially a U.K. power generator, by accessing internet-exposed devices with default credentials and taking them offline.
Iran-linked group previously associated with targeting industrial control systems, including Unitronics PLCs used in multiple sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.