The U.S. State Department's Rewards for Justice program offered up to $10 million for information identifying or locating Amir Yaryab, whom U.S. officials describe as a senior official leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command's Cyber Operations Command. The U.S. alleges that Yaryab directs cyber units targeting critical infrastructure across the United States, Europe, and the Middle East, including the defense, news, shipping, water, and wastewater sectors.
The announcement links Yaryab and the IRGC-CEC to CyberAv3ngers and Dadeh Afzar Arman. CyberAv3ngers reportedly compromised at least 75 internet-exposed Unitronics Vision Series PLCs between November 2023 and January 2024, including 34 in U.S. water and wastewater organizations, by abusing default or missing passwords. The intrusions reportedly altered PLC ladder logic, credentials, and configurations and defaced HMIs, risking disruption to industrial processes; operators should eliminate direct internet exposure of OT devices, enforce strong authentication, patch affected systems, and secure remote access through VPNs and firewalls.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
CyberAv3ngers reportedly conducted attack waves against internet-exposed Unitronics Vision Series PLCs, exploiting default or absent passwords. The activity ran from November 2023 through January 2024 and included at least 75 compromised PLCs, 34 of them in the U.S. water and wastewater sector.
A joint advisory by CISA, the FBI, NSA, EPA, and international partners reported that IRGC-connected actors began compromising Israeli-made Unitronics Vision Series PLCs in late 2023. Reported intrusions included ladder-logic changes, configuration and credential tampering, and HMI defacements.
The U.S. State Department's Rewards for Justice program offered up to $10 million for information identifying or locating Amir Yaryab, whom U.S. officials allege leads IRGC Cyber-Electronic Command cyber operations. Authorities linked him to IRGC-affiliated groups including CyberAv3ngers and Dadeh Afzar Arman and alleged their targeting of critical-infrastructure sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcerewardsforjustice.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.