CyberAv3ngers is an Iran-linked, state-directed threat actor associated with the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) and focused primarily on operational technology and industrial control systems. The group is widely tracked under aliases including Bauxite, Storm-0784, UNC5691, Shahid Kaveh Group, Soldiers of Solomon, and Cyber_Av3ngers. Reporting also associates it with the ATT&CK group designation G1027. CyberAv3ngers presents itself as a hacktivist persona, but U.S. government attribution and sanctions activity have tied its operations to IRGC-directed cyber activity, making it better understood as a state-backed proxy or front rather than an independent activist collective. CyberAv3ngers is best known for targeting critical infrastructure sectors that rely on industrial control systems, especially water and wastewater, energy, government services, healthcare, food and beverage manufacturing, and fuel-management environments. Its targeting has shown a recurring focus on Israeli-manufactured technology and on U.S. and allied civilian infrastructure. Early public activity in 2023 centered on compromises of internet-exposed Unitronics Vision Series PLCs and HMIs, often through default credentials, resulting in defacements and operational disruption. Those campaigns affected dozens of devices across the United States and other countries and demonstrated the group’s willingness to target civilian OT environments for coercive and psychological effect. The actor subsequently evolved from opportunistic exposed-device abuse into more capable malware-backed OT operations. In 2024, CyberAv3ngers was linked to IOCONTROL, a custom Linux malware platform for embedded OT and IoT devices. IOCONTROL has been described as a backdoor for Linux-based edge and control-adjacent systems, including routers, gateways, cameras, firewalls, HMIs, PLC-adjacent devices, and fuel-management systems. Its capabilities include persistence, encrypted configuration handling, device profiling, arbitrary command execution, internal scanning, exfiltration of command output, self-deletion, and MQTT-based command and control. This marked a significant escalation from symbolic defacement activity to repeatable implant-enabled access in OT-adjacent environments. By 2026, CyberAv3ngers was also linked to active exploitation of CVE-2021-22681 affecting Rockwell Automation Logix environments. U.S. government reporting stated that Iranian-affiliated actors used legitimate engineering software against internet-facing PLCs, causing operational disruption and financial loss in government services, water and wastewater, and energy organizations. The group’s tradecraft in these campaigns emphasized exploitation of weakly secured or directly exposed industrial assets rather than novel zero-days, including abuse of default credentials, insecure remote access, exposed HMIs and PLCs, and poor IT/OT segmentation. CyberAv3ngers combines disruptive OT intrusion activity with influence operations and exaggerated or fabricated claims. It has repeatedly used propaganda, defacement messaging, and public claims to amplify psychological impact, and some claimed incidents have reportedly reused older material or overstated operational effects. Even so, the actor has demonstrated credible access to real industrial environments, and its operational trajectory shows increasing maturity in OT targeting. Open-source reporting also indicates the group used generative AI for programmable logic controller reconnaissance and code debugging, suggesting adoption of AI as a force multiplier for industrial targeting research. Related malware and code lineage discussed alongside CyberAv3ngers includes IOCONTROL and the destructive code family Crucio; some reporting also connects associated destructive tooling to FlockWiper and GigaWiper/BLUERABBIT code lineage. CyberAv3ngers has additionally been linked in some reporting to overlap or continuity with other Iran-aligned personas and infrastructure, though not all such relationships are equally well established. Overall, CyberAv3ngers represents one of the clearest examples of an Iranian state-linked actor specializing in OT and ICS disruption. Its progression from hacktivist branding and PLC defacements to custom embedded malware and exploitation of industrial controller weaknesses makes it a significant threat to civilian critical infrastructure, particularly where internet exposure, default credentials, and weak remote-access controls remain unresolved.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The group pivoted to exploiting CVE-2021-22681, a critical authentication bypass vulnerability (CVSS 9.8) in Rockwell Automation Logix controllers. Actors used leased overseas infrastructure with Rockwell's Studio 5000 Logix Designer software to connect to internet-facing PLCs, bypassing authentication to manipulate project files and HMI/SCADA displays.
On Monday, the U.S. Cybersecurity and Infrastructure Security Agency added the Unitronics bug to its Known Exploited Vulnerabilities catalog, assigning it CVE-2023-6448. The advisory warned that “Unitronics Vision Series PLCs and HMIs [Human Machine Interfaces] use default administrative passwords.” “An unauthenticated attacker with network access to a PLC or HMI can take administrative control of the system,” the agency said.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked actor using AI-assisted reconnaissance against PLCs and ICS environments, supporting critical infrastructure targeting.
Iran-linked persona using AI-assisted reconnaissance against PLCs/ICS, supporting attacks on industrial control systems and critical infrastructure.
Iran-linked threat group referenced because a precursor/destructive component (Crucio) was previously associated with it in a CISA advisory.
IRGC-affiliated actor targeting internet-exposed Unitronics Vision Series PLCs in critical infrastructure sectors using default credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.