Cyber Av3ngers — APT Profile

Cyber Av3ngers is an Iranian state-directed intrusion set that operates behind a pro-Palestinian hacktivist persona; MITRE ATT&CK tracks it as G1027, a "suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated APT group" active since at least 2020. In February 2024 the U.S. Treasury sanctioned six officials of the IRGC Cyber-Electronic Command (IRGC-CEC) for directing its operations, and the State Department's Rewards for Justice programme offers up to $10 million for information on the group and its "Mr. Soul" persona. Its best-known campaign, covered by the CISA/FBI/NSA/EPA joint advisory AA23-335A, compromised internet-exposed Unitronics Vision-series PLCs at water, energy and healthcare sites in the United States, Ireland and elsewhere from November 2023, logging in with factory default credentials and defacing operator screens with anti-Israel messaging rather than seeking extortion. Dragos tracks a heavily overlapping activity cluster as BAUXITE, which it says "shares substantial technical overlaps with the pro-Iranian hacktivist persona CyberAv3ngers" without equating the two, and links that cluster to the IOCONTROL modular implant for Linux-based OT and IoT devices.

Also tracked as

CyberAvengers, CyberAv3ngers, Bauxite, Storm-0784, Hydro Kitten, UNC5691, Shahid Kaveh Group, Mr. Soul, Soldiers of Solomon

IntelFusions coverage (8)

Tools & malware

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions