Cyber Av3ngers — APT Profile
Cyber Av3ngers is an Iranian hacktivist group linked to IRGC that attacked US water utilities by exploiting Unitronics PLCs.Also tracked as
CyberAvengers, CyberAv3ngers, Bauxite, Storm-0784, Hydro Kitten, UNC5691, Shahid Kaveh Group, Mr. Soul, Soldiers of Solomon
IntelFusions coverage (8)
- Hackers lock water utilities out of internet-facing PLCs 2026-07-31 · Cyber Incidents
- CISA flags critical bugs in Rockwell and ABB industrial gear 2026-07-15 · Vulnerabilities
- Attacks on industrial control systems fall to a three-year low 2026-07-07 · Cyber Incidents
- CISA warns of critical flaws across industrial control systems 2026-06-30 · Vulnerabilities
- Critical flaws let attackers hijack EV charging networks 2026-06-26 · Vulnerabilities
- Iran's Hackers Are Shifting From Spying to Sabotaging US Infrastructure 2026-06-09 · Nation-State
- Hacktivism-as-a-Service: How Keymous+ Monetized Disruption Through the EliteStress DDoS Platform 2026-02-16 · Cyber Incidents
- IRGC-Affiliated CyberAv3ngers Target Unitronics PLCs in Water, Energy, and Healthcare Sectors Across Multiple Countries 2026-02-16 · Nation-State
Tools & malware
- IOCONTROL Backdoor
Vendor research
- Inside a New OT/IoT Cyberweapon: IOCONTROL Claroty (Team82)
- BAUXITE (Threat Group) Dragos
- Cyber Av3ngers Hacktivist Group Targeting Israel-Made OT Devices Dragos
- AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure CISA (with FBI, NSA, EPA, DOE, CNMF)
- AA23-335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities CISA (with FBI, NSA, EPA, INCD, CCCS, NCSC-UK)
- Treasury Sanctions Actors Responsible for Malicious Cyber Activities on Critical Infrastructure U.S. Department of the Treasury
Countries linked to this actor
- United States targets
- Ireland targets
- Israel targets