Skip to content
IranState-SponsoredActive

CyberAv3ngers

IRGC cyber unit operating under a hacktivist persona. Defaced water-utility PLCs across the U.S. by exploiting a default password.

ATTRIBUTED TOIran › IRGC — Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) › IRGC-CEC

Download profile JSON
Active
2020–present
Motivation
Sabotage / Destruction, Information Operations, Hacktivism
Aliases
6
Exploited CVEs
1
ATT&CK techniques
8
Cited sources
6

Overview

CyberAv3ngers presents itself as a hacktivist collective. The U.S. Treasury identifies it as the Islamic Revolutionary Guard Corps Cyber-Electronic Command — an official military unit using a persona as cover.

Its November 2023 operation is the clearest recent illustration of how little sophistication a consequential attack on critical infrastructure requires. The group targeted Unitronics Vision series programmable logic controllers — devices that control physical processes at water and wastewater utilities. It did not exploit a memory corruption bug or develop a novel technique. It found internet-exposed PLCs still using the vendor's default password of "1111," logged in, and replaced the operator interface with an anti-Israel message.

The Municipal Water Authority of Aliquippa in Pennsylvania was among the affected utilities, and had to switch to manual operation. Others were hit across multiple U.S. states. The attack caused no confirmed contamination or water-supply failure — but the same access that defaced a screen could have manipulated pressure, chemical dosing, or pump control.

The choice of Unitronics equipment appears to have been driven by the manufacturer being Israeli rather than by the strategic value of any particular victim. Small U.S. water utilities, most with no security staff, were collateral in a geopolitical message.

In February 2024 the U.S. Treasury sanctioned six IRGC-CEC officials, and the State Department's Rewards for Justice programme offered up to $10 million for information on the group.

Attribution

Down to the named unit where public evidence supports it.

IranIRGC — Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC)IRGC-CECConfirmed

The U.S. Department of the Treasury sanctioned six IRGC-CEC officials in February 2024, naming them in connection with the CyberAv3ngers persona and the November 2023 attacks on Unitronics PLCs at U.S. water utilities. A joint advisory from CISA, FBI, NSA, EPA, and the Israel National Cyber Directorate documented the technical detail. The State Department subsequently offered a reward of up to $10 million for information on the actors.

Attributing sources

Cross-vendor naming crosswalk

6 designators across 6 organisations.

1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

Microsoft Threat Intelligence

index ↗
  • CyberAv3ngers

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • CyberAv3ngers

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • CyberAv3ngers

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Palo Alto Networks Unit 42

index ↗
  • CyberAv3ngers

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Dragos

index ↗
  • BAUXITEpartialDragos assesses BAUXITE as overlapping with CyberAv3ngers activity against ICS

Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.

CISA / NSA / FBI

index ↗
  • CyberAv3ngers / IRGC-CEC

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

IOCONTROLmalware

Modular Linux implant for IoT and OT devices — routers, PLCs, HMIs, fuel management systems — using MQTT for C2.

Shared, commodity & living-off-the-land

Default credentialslotl

The primary technique — internet-exposed Unitronics PLCs still using the vendor default password '1111'.

Shodan / internet scanningutility

Mass identification of internet-exposed industrial devices by vendor and model.

HMI defacementutility

Replacement of operator interface screens with political messaging, visible to plant staff.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by CyberAv3ngers
CVE-2023-6448KEV9.822 Nov 2023Unitronics Vision PLCs shipping with the default password '1111' and exposed directly to the internet. No exploit development required — the group logged in and replaced the operator interface. Multiple U.S. water utilities were forced to manual operation.SRCCISA / FBI / NSA / EPA / INCD

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

4 stages · 8 techniques
  1. 01

    Reconnaissance

    1 technique

    Scans the internet for exposed industrial equipment by vendor and model. The selection criterion in November 2023 was not the victim's importance but the manufacturer's nationality — Unitronics is Israeli, so its customers became targets.

  2. 03

    Command and Control

    1 technique

    IOCONTROL, a modular Linux implant for routers, PLCs, HMIs and fuel management systems, using MQTT — a protocol these devices already speak — for control.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

8 techniques across 4 tactics · 7 with actor-specific notes

Reconnaissance

1

Initial Access

3

Command and Control

1

Impact

3

Campaign timeline

  1. U.S. Water Utility PLC Defacements

    Compromise of internet-exposed Unitronics PLCs at water and wastewater utilities across multiple U.S. states using the vendor's default password. The Municipal Water Authority of Aliquippa was forced to manual operation. The equipment was selected because the manufacturer is Israeli, not because the victims mattered.

    CVE-2023-6448Water & WastewaterCritical Infrastructure

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.