CyberAv3ngers is an Iran-linked threat actor and hacktivist-branded persona assessed to operate on behalf of, or under the direction of, the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). The group is widely tracked under aliases including Bauxite, Storm-0784, UNC5691, Shahid Kaveh Group, Soldiers of Solomon, and related stylizations of its name. It presents itself publicly as an ideological anti-Israel actor, but multiple government and industry assessments have tied it to state-directed Iranian cyber operations. CyberAv3ngers is notable for targeting operational technology and industrial control systems, especially internet-exposed programmable logic controllers, human-machine interfaces, and OT-adjacent embedded devices. Its victimology has included water and wastewater systems, energy infrastructure, government facilities, healthcare, food and beverage manufacturing, fuel-management environments, and other civilian critical infrastructure in the United States and allied countries. The group has shown a particular focus on Israeli-manufactured technology and on organizations whose disruption would generate psychological and political impact. The actor first gained broad attention through campaigns against Unitronics Vision Series PLCs, where it exploited default credentials on internet-exposed devices to gain access, alter interfaces, and conduct disruptive or propagandistic operations. These intrusions demonstrated that CyberAv3ngers often relies on weak security posture rather than advanced initial access tradecraft, including exposed remote administration, poor segmentation, and insecure OT deployments. Subsequent reporting linked the group to compromises affecting water-sector entities and other critical infrastructure operators. CyberAv3ngers later evolved beyond opportunistic PLC defacement into malware-enabled OT access. It has been attributed with IOCONTROL, a custom Linux/ARM backdoor designed for embedded OT and IoT environments. IOCONTROL supports persistence, encrypted configuration handling, MQTT-based command and control, device profiling, arbitrary command execution, internal scanning, exfiltration of command output, and self-deletion. Targeted device classes have included routers, gateways, firewalls, cameras, HMIs, PLC-adjacent systems, and fuel-management controllers. This progression indicates a shift from symbolic disruption toward repeatable, persistent access in operational environments. By 2026, CyberAv3ngers was also associated with active exploitation of Rockwell Automation Logix ecosystem weaknesses affecting internet-facing PLC environments in U.S. critical infrastructure. Public reporting assessed that these operations caused operational disruption and financial loss in sectors including government services, water and wastewater, and energy. The group’s tradecraft in these campaigns included use of legitimate engineering software, manipulation of project files and operator displays, and abuse of poorly secured remote access paths. The actor combines cyber intrusion with influence and intimidation activity. It has repeatedly used public claims, defacements, Telegram messaging, and politically themed narratives to amplify the perceived impact of its operations. Some claims attributed to the persona have reportedly mixed genuine access with exaggerated, recycled, or fabricated material, consistent with a dual mission of disruption and psychological effect. This hacktivist presentation provides deniability while supporting Iranian state objectives. CyberAv3ngers has also been cited in reporting on Iranian use of generative AI and large language models for cyber operations, including reconnaissance on PLC technologies and assistance with technical research and code debugging. These uses appear to enhance existing operational workflows rather than represent wholly new capabilities. The group is part of the broader Iranian cyber ecosystem that blends state operators, front personas, and aligned proxy or hacktivist brands. Within that ecosystem, CyberAv3ngers stands out as one of the clearest IRGC-linked actors focused on OT and ICS disruption. Its activity illustrates Iran’s use of deniable cyber personas to target civilian critical infrastructure, especially where insecure internet exposure and default credentials create low-cost opportunities for coercive or disruptive effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The group pivoted to exploiting CVE-2021-22681, a critical authentication bypass vulnerability (CVSS 9.8) in Rockwell Automation Logix controllers. Actors used leased overseas infrastructure with Rockwell's Studio 5000 Logix Designer software to connect to internet-facing PLCs, bypassing authentication to manipulate project files and HMI/SCADA displays.
On Monday, the U.S. Cybersecurity and Infrastructure Security Agency added the Unitronics bug to its Known Exploited Vulnerabilities catalog, assigning it CVE-2023-6448. The advisory warned that “Unitronics Vision Series PLCs and HMIs [Human Machine Interfaces] use default administrative passwords.” “An unauthenticated attacker with network access to a PLC or HMI can take administrative control of the system,” the agency said.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked hacktivist-fronted operation tied in the article to IRGC Cyber-Electronic Command activity and OT-focused targeting.
Iran-linked actor using AI-assisted reconnaissance against PLCs and ICS environments, supporting critical infrastructure targeting.
Iran-linked persona using AI-assisted reconnaissance against PLCs/ICS, supporting attacks on industrial control systems and critical infrastructure.
Iran-linked threat group referenced because a precursor/destructive component (Crucio) was previously associated with it in a CISA advisory.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.