Cyber Av3ngers — APT Profile
Cyber Av3ngers is an Iranian state-directed intrusion set that operates behind a pro-Palestinian hacktivist persona; MITRE ATT&CK tracks it as G1027, a "suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated APT group" active since at least 2020. In February 2024 the U.S. Treasury sanctioned six officials of the IRGC Cyber-Electronic Command (IRGC-CEC) for directing its operations, and the State Department's Rewards for Justice programme offers up to $10 million for information on the group and its "Mr. Soul" persona. Its best-known campaign, covered by the CISA/FBI/NSA/EPA joint advisory AA23-335A, compromised internet-exposed Unitronics Vision-series PLCs at water, energy and healthcare sites in the United States, Ireland and elsewhere from November 2023, logging in with factory default credentials and defacing operator screens with anti-Israel messaging rather than seeking extortion. Dragos tracks a heavily overlapping activity cluster as BAUXITE, which it says "shares substantial technical overlaps with the pro-Iranian hacktivist persona CyberAv3ngers" without equating the two, and links that cluster to the IOCONTROL modular implant for Linux-based OT and IoT devices.Also tracked as
CyberAvengers, CyberAv3ngers, Bauxite, Storm-0784, Hydro Kitten, UNC5691, Shahid Kaveh Group, Mr. Soul, Soldiers of Solomon
IntelFusions coverage (8)
- Hackers lock water utilities out of internet-facing PLCs 2026-07-31 · Cyber Incidents
- CISA flags critical bugs in Rockwell and ABB industrial gear 2026-07-15 · Vulnerabilities
- Attacks on industrial control systems fall to a three-year low 2026-07-07 · Cyber Incidents
- CISA warns of critical flaws across industrial control systems 2026-06-30 · Vulnerabilities
- Critical flaws let attackers hijack EV charging networks 2026-06-26 · Vulnerabilities
- Iran's Hackers Are Shifting From Spying to Sabotaging US Infrastructure 2026-06-09 · Nation-State
- Hacktivism-as-a-Service: How Keymous+ Monetized Disruption Through the EliteStress DDoS Platform 2026-02-16 · Cyber Incidents
- IRGC-Affiliated CyberAv3ngers Target Unitronics PLCs in Water, Energy, and Healthcare Sectors Across Multiple Countries 2026-02-16 · Nation-State
Tools & malware
- IOCONTROL Backdoor
- mr_soul_controller operator script used with the oblivator wiper module
- oblivator wiper module used to wipe Linux device files
Vendor research
- IOControl Malware: What is New, What is Not? Armis
- BAUXITE (Threat Group) Dragos
- Cyber Av3ngers Hacktivist Group Targeting Israel-Made OT Devices Dragos
- Inside a New OT/IoT Cyberweapon: IOCONTROL Claroty (Team82)
- AA23-335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities CISA (with FBI, NSA, EPA, INCD, CCCS, NCSC-UK)
- Treasury Sanctions Actors Responsible for Malicious Cyber Activities on Critical Infrastructure U.S. Department of the Treasury
- AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure CISA (with FBI, NSA, EPA, DOE, CNMF)
Countries linked to this actor
- United States targets
- Ireland targets
- Israel targets