CyberAv3ngers is an Iranian state-linked cyber threat actor and hacktivist persona associated with the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). The group is widely tracked under aliases including Shahid Kaveh Group, Storm-0784, Bauxite, UNC5691, and CL-STA-1128; some reporting also associates it with Hydro Kitten. It presents itself as a hacktivist brand, but public attribution and sanctions actions have tied its operations to Iranian state direction. CyberAv3ngers is best known for disruptive operations against operational technology and industrial control systems, especially internet-exposed programmable logic controllers, HMIs, and OT-adjacent embedded devices. Its targeting has centered on critical infrastructure, including water and wastewater systems, energy, government and municipal facilities, and in some reporting healthcare and food and beverage manufacturing. The group has shown particular interest in exposed devices protected by default or weak credentials and in Israeli-linked technology, while later campaigns expanded to broader U.S. critical infrastructure. In late 2023 and early 2024, CyberAv3ngers conducted a high-profile campaign against Unitronics Vision Series PLCs, compromising dozens of internet-exposed devices and replacing legitimate logic or defacing interfaces. Subsequent activity demonstrated an evolution from opportunistic access and propaganda-oriented disruption toward more operationally significant OT intrusion tradecraft. By 2024, the group was linked to IOCONTROL, a custom Linux/ARM malware platform for OT and IoT environments that provides persistence, remote command execution, device profiling, scanning, exfiltration, and self-delete capabilities using MQTT-based command and control. IOCONTROL has been associated with targeting of embedded devices such as fuel-management systems, routers, gateways, cameras, firewalls, PLCs, and HMIs, indicating a shift toward repeatable implant-enabled access in OT-adjacent environments. By 2026, Iranian-affiliated activity linked to CyberAv3ngers was associated with active exploitation of internet-connected PLCs from multiple vendors across U.S. critical infrastructure sectors. Observed tradecraft included direct access to exposed PLCs, use of legitimate vendor engineering software, exfiltration of project files, modification or deletion of controller logic, insertion or alteration of reusable logic components, manipulation of HMI and SCADA displays, and in some cases disabling of shutdown and alarm functions. Reported effects included operational disruption, financial loss, and creation of unsafe operating conditions without alerting operators. The activity has been characterized as opportunistic and exposure-driven rather than dependent on novel exploitation chains. CyberAv3ngers has also been reported to use remote access tooling on victim-connected infrastructure and to abuse legitimate administration and engineering workflows rather than relying exclusively on bespoke ICS malware. ATT&CK behaviors associated with its campaigns include Internet Accessible Device, Commonly Used Port, Remote Access Tools, Exfiltration Over C2 Channel, and Data Manipulation. Beyond technical intrusion, CyberAv3ngers operates as an influence and intimidation persona, blending genuine compromises with exaggerated or fabricated public claims to amplify psychological impact. This combination of disruptive OT targeting, deniable hacktivist branding, and information operations makes the actor notable within Iran’s broader cyber ecosystem. Treasury sanctions against IRGC-CEC officers over CyberAv3ngers activity further reinforce the assessment that the persona functions as a state-directed front rather than an independent hacktivist collective.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The group pivoted to exploiting CVE-2021-22681, a critical authentication bypass vulnerability (CVSS 9.8) in Rockwell Automation Logix controllers. Actors used leased overseas infrastructure with Rockwell's Studio 5000 Logix Designer software to connect to internet-facing PLCs, bypassing authentication to manipulate project files and HMI/SCADA displays.
On Monday, the U.S. Cybersecurity and Infrastructure Security Agency added the Unitronics bug to its Known Exploited Vulnerabilities catalog, assigning it CVE-2023-6448. The advisory warned that “Unitronics Vision Series PLCs and HMIs [Human Machine Interfaces] use default administrative passwords.” “An unauthenticated attacker with network access to a PLC or HMI can take administrative control of the system,” the agency said.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian-affiliated OT disruption activity targeting internet-connected PLCs and other operational technology in US critical infrastructure, including manipulation of project files, HMI/SCADA data, and in prior activity compromise of Unitronics devices in the water sector.
Referenced as a prior Iran-linked group associated with attacks on critical infrastructure and exposed industrial control equipment; mentioned for comparison to the current campaign.
Iran-linked group described as a hacktivist persona used in attacks targeting ICS/OT systems.
Iranian-affiliated threat activity targeting internet-connected PLCs in U.S. critical infrastructure, manipulating PLC project files, HMI/SCADA displays, and operational processes to cause disruption and financial loss.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.