TLP:CLEAR
⚠ NATION-STATE · IRGC-CEC · IRAN
// Threat Actor Profile — State-Directed ICS/OT Sabotage Operation Presented Publicly as Hacktivism

CYBERAV3NGERS

PROFILE COMPILED: 2026-09-12  |  PREVIOUSLY COMPILED: 2026-09-02  |  SOURCES: MITRE ATT&CK (G1027), CISA/FBI/NSA/EPA Joint Advisories AA23-335A & AA26-097A, U.S. Treasury/OFAC, Claroty Team82, Mandiant, Microsoft, Dragos, Tenable, WaterISAC, 15+ additional vendor/press sources
Status: ACTIVE — ESCALATING, NATIONAL-SCALE OT TARGETING
Threat Level: CRITICAL
Primary Motive: State-Directed Critical-Infrastructure Disruption — publicly framed as anti-Israel/anti-US hacktivism
Active Since: 2020 (assessed) / Oct 2023 (public persona)
MITRE ATT&CK: G1027
⚡ THREAT UPDATE — JUL 2026
Coordinated strike on 30+ Minnesota water utilities exposes national exposure of unpatched Rockwell PLCs
On 2026-07-26/27, a coordinated cyberattack disrupted more than 30 municipal water systems across Minnesota — including Plymouth, South St. Paul, Maple Plain, and Braham — by remotely accessing internet-exposed Rockwell Automation/Allen-Bradley MicroLogix 1100/1400 PLCs and changing device IP addresses and passwords to lock legitimate operators out. One treatment plant went fully offline, at least two cities reverted to manual operation, and one mayor declared a local state of emergency; Minnesota's Department of Health confirmed no water-quality impact and no boil-water advisories resulted (Tenable, 2026; The Register, 2026). By 2026-07-30 the FBI and EPA confirmed water/wastewater intrusions in at least seven U.S. states. Tenable assesses the operational pattern — Rockwell PLC targeting, IP/credential lockout technique — as consistent with CyberAv3ngers' established modus operandi, though neither state nor federal officials had issued formal attribution as of this compile. The incident follows directly from the seven-agency joint advisory AA26-097A (2026-04-07), which confirmed CyberAv3ngers/IRGC-CEC exploitation of the still-unpatched CVE-2021-22681 Rockwell Logix authentication bypass, with expansion to Schneider Electric and Siemens devices via malicious project files designed to override safety-critical logic.
75+
Unitronics Vision PLCs Compromised Across US, Israel, UK & Ireland (2023 Wave)
$10M
U.S. State Department Rewards for Justice Bounty on the Group
30+
Minnesota Water Utilities Hit in a Single Coordinated Attack, Jul 26–27 2026
7+
US States Reporting Water/Wastewater Intrusions as of Jul 30 2026
00
Overview

CyberAv3ngers is a state-directed cyber unit of Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) that operates publicly as a self-presented "hacktivist" collective, active since at least 2020 and tracked under the MITRE ATT&CK designation G1027. It is tracked in industry reporting under a wide alias set — Soldiers of Solomon, Shahid Kaveh Group, and Hydro Kitten/UNC5691 (Mandiant), Storm-0784 (Microsoft), and Bauxite (Dragos) — reflecting independent convergence across multiple vendors and government agencies on the same underlying actor. Unlike most nation-state-linked groups this profile series covers, CyberAv3ngers is defined not by espionage or financial theft but by direct sabotage-oriented targeting of operational technology (OT) and industrial control systems (ICS): programmable logic controllers (PLCs), human-machine interfaces (HMIs), and the physical processes they govern.

The group matters acutely right now because its capability and reach have escalated sharply and repeatedly since its public debut. What began in November 2023 as opportunistic exploitation of a single default administrative password ("1111") on internet-exposed Unitronics Vision Series PLCs — compromising a booster station at the Municipal Water Authority of Aliquippa, Pennsylvania, among at least 75 devices worldwide — had by April 2026 escalated into a six-agency U.S. joint advisory (AA26-097A) confirming active exploitation of an unpatched, four-year-old Rockwell Automation authentication-bypass vulnerability (CVE-2021-22681) across water, energy, and government infrastructure nationally, plus expansion to Schneider Electric and Siemens devices via malicious project files engineered to override safety-critical logic. That trajectory culminated, as of this compile, in a coordinated July 2026 strike that knocked out or degraded operator control at 30-plus Minnesota water utilities in a single 24-hour window, with confirmed intrusions spanning at least seven U.S. states.

CyberAv3ngers sits at the center of a specific geopolitical function: its hacktivist framing supplies Iran a layer of public deniability for actions against U.S. and Israeli critical infrastructure amid sustained regional tension, while U.S. Treasury, CISA, and multiple private-sector vendors have explicitly and publicly pierced that framing. OFAC sanctioned six named IRGC-CEC officials — including Hamid Reza Lashgarian, head of the IRGC-CEC and a commander in the IRGC-Qods Force — in February 2024, alongside a $10 million State Department bounty, formally establishing state attribution well before the group's most consequential 2026 activity.

The critical operational context defenders should hold in mind: CyberAv3ngers' core enabling condition has never been sophisticated malware. It is the routine, often unnecessary practice of exposing PLC and HMI management interfaces directly to the public internet — disproportionately common among small, rural, and municipal water utilities operating with minimal dedicated OT security investment. The group has now demonstrated, repeatedly and at increasing scale despite sanctions, an indictment-adjacent bounty program, and multiple public advisories, that this structural weakness across the U.S. water sector remains exploitable on demand.

01
Identity & Attribution
Primary NameCyberAv3ngers
Sponsor / ParentIran's Islamic Revolutionary Guard Corps — Cyber-Electronic Command (IRGC-CEC)
Actor TypeNation-State — OT/ICS Sabotage, operating under a self-presented "hacktivist" persona
Primary MotivationState-directed critical-infrastructure disruption and pre-positioning, publicly framed as anti-Israel/anti-US political retaliation
Active SinceAt least 2020 (MITRE-assessed); public operations under the CyberAv3ngers persona since October 2023
Last Observed2026 — coordinated Minnesota water-utility campaign (Jul 2026); "Cyber4vengers" Telegram persona active since Jan 2026
MITRE G-IDG1027
Legal StatusOFAC sanctioned six IRGC-CEC officials (Feb 2024, incl. commander Hamid Reza Lashgarian); U.S. State Dept. Rewards for Justice $10M bounty (Feb 2024)
Tracking Aliases
CyberAv3ngers Soldiers of Solomon Shahid Kaveh Group Hydro Kitten UNC5691 Storm-0784 Bauxite Cyber4vengers (2026 rebrand)
Attribution Confidence

Attribution to Iran's IRGC-CEC is HIGH, supported by multiple fully independent lines of evidence: joint U.S. government advisories (CISA/FBI/NSA/EPA — AA23-335A and AA26-097A), formal U.S. Treasury/OFAC sanctions naming specific IRGC-CEC officers as directing operations, and separate, independently arrived-at technical attribution from Mandiant, Microsoft, Dragos, and Claroty. This is a case where government and private-sector attribution converge exceptionally cleanly, and where the actor's own "hacktivist" self-presentation has been explicitly and publicly rejected by attributing bodies rather than merely doubted. The residual uncertainty is not sponsorship but internal structure: the precise division of labor between the propaganda/persona-management layer (serial Telegram rebrands, frequently exaggerated or fabricated claims) and the technical operators executing PLC exploitation is not fully resolved, and these may not be the same individuals or sub-unit.

02
Campaign & Operational Timeline
2020
Assessed Origins
MITRE ATT&CK dates group activity to at least 2020, predating the group's public persona; limited public detail exists on this earliest period.
OCT 2023
Public Persona Launch — Israel-Focused Claims
CyberAv3ngers begins publicly claiming attacks against Israeli infrastructure via Telegram: the Dorad power station (Oct 8 — later found to reuse material recycled from an earlier Moses Staff hacktivist leak), ORPAK fuel-station systems, and 10 Israeli water treatment stations (Oct 30). Multiple claims from this period were subsequently assessed by researchers as exaggerated or fabricated.
NOV 2023
Pivot to US Critical Infrastructure — Unitronics Campaign
Exploits the default "1111" administrative password on internet-exposed Unitronics Vision Series PLCs/HMIs; compromises a booster-station PLC at the Municipal Water Authority of Aliquippa, PA (Nov 25) and at least 75 devices total across the US, Israel, UK, and Ireland. Joint CISA/FBI/NSA/EPA/INCD advisory AA23-335A follows.
NOV 2023 –
APR 2024
Sustained US ICS/OT Intrusion Wave
At least 29 confirmed intrusions against U.S. ICS/OT assets are attributed to the group in this window, extending beyond water utilities into other sectors running Unitronics and related equipment.
FEB 2024
OFAC Sanctions & $10M Bounty
U.S. Treasury/OFAC sanctions six IRGC-CEC officials directing operations, including commander Hamid Reza Lashgarian; the State Department simultaneously announces a $10M Rewards for Justice bounty for information on the group.
APR 2024
OPSEC Failure — Persona Comms Disrupted
The group's Telegram communications are disrupted, assessed by researchers as possibly linked to poor operational security that may have enabled geolocation of persona operators.
2024 –
2025
IOCONTROL Malware Development
The group develops IOCONTROL, a custom, modular Linux malware platform for OT/IoT devices spanning routers, PLCs, HMIs, IP cameras, and firewalls from at least nine distinct vendors. Claroty Team82 publishes detailed technical analysis in December 2024, characterizing it as a nation-state cyberweapon.
JAN 2026
"Cyber4vengers" Rebrand
After the "APT IRAN" Telegram channel — widely assessed as a prior CyberAv3ngers rebrand — is deleted, "Cyber4vengers" emerges to continue persona operations, illustrating the group's resilience to platform-level takedowns.
MAR –
APR 2026
Escalation to Rockwell/Schneider/Siemens — AA26-097A
Campaign expands to exploit unpatched CVE-2021-22681 in Rockwell Automation Logix controllers, then to Schneider Electric and Siemens devices via malicious project files designed to override safety-critical logic. A seven-agency advisory (AA26-097A, Apr 7) — FBI, CISA, NSA, EPA, DOE, U.S. Cyber Command's CNMF, and the Department of the Treasury — confirms operational disruption and financial loss at multiple U.S. organizations.
JUL 2026
Coordinated Minnesota Water-Utility Attack
On Jul 22 the authoring agencies update AA26-097A — expanding confirmed vendor scope beyond Rockwell to Schneider Electric, Siemens and potentially other manufacturers, and adding detection guidance for malicious modification of Add-On Instructions (AOIs) inside Rockwell PLC programs. Four days later, 30+ Minnesota water systems are hit Jul 26–27 via compromised Rockwell/Allen-Bradley MicroLogix 1100/1400 PLCs, with attackers changing device IP addresses and passwords to lock out operators. MNIT puts the confirmed total at ~36 systems. One plant (Braham) goes offline for over an hour; Plymouth and South St. Paul revert to manual operation; Maple Plain declares a local emergency. In Clayton County, Georgia, a pump station failure on Jul 27 triggers a precautionary boil-water advisory. FBI/EPA confirm intrusions across at least seven U.S. states by Jul 30; later reporting extends this to at least twelve states, with U.S. investigators assessing 100+ facilities targeted (NYT, Jul 30 2026). A group posting as "APT Iran" claims direct responsibility on Telegram alongside CyberAv3ngers, describing the operation as a warning (Check Point Research). Formal event-level government attribution remained pending as of this compile. (see incident card: 2026-07-26_US-WATER-SECTOR-PLC-CAMPAIGN)
03
Attack Lifecycle Internet-exposed OT, not sophisticated intrusion, is the primary access vector

CyberAv3ngers' intrusion lifecycle begins almost entirely with internet-facing reconnaissance rather than social engineering or supply-chain compromise: Shodan- and Censys-style sweeps for OT/ICS devices exposed directly to the public internet, keyed to known default service ports — TCP 20256 for Unitronics Vision Series PLCs, TCP 44818 for Rockwell EtherNet/IP-enabled controllers (T1595.002). Because so many small and municipal utilities operate these devices without any VPN, firewall segmentation, or network isolation between the management interface and the open internet (T1133), a successful scan alone frequently yields direct administrative reach to a live industrial process.

Initial access itself has evolved but has consistently avoided the need for sophisticated exploitation until relatively recently. The 2023 Unitronics campaign required nothing more than the PLC/HMI's unmodified factory-default administrative password, "1111" (T1078.001) — no malware, no exploit, and no credential theft was necessary. The 2026 Rockwell campaign marks a genuine sophistication increase: it weaponizes CVE-2021-22681, a critical authentication-bypass flaw in the cryptographic key used to verify communications between Rockwell's engineering software and Logix-family controllers, for which Rockwell has never issued a firmware patch (T1190). Once inside, the group has needed almost no lateral movement in the traditional IT sense, because the compromised device — a PLC or HMI — is itself the target and the endpoint of impact.

Where impact requires more than administrative access to native device functions, the group deploys IOCONTROL, its custom, modular Linux malware platform for OT/IoT devices. IOCONTROL installs a persistence mechanism via an rc.d boot script (T1037.004) and communicates with its operators over MQTT/TLS on port 8883 — a standard IoT protocol chosen specifically to blend command-and-control traffic with legitimate device telemetry — while resolving C2 domains via DNS-over-HTTPS to defeat DNS-based blocking (T1071, T1071.004). Its configuration is AES-256-CBC encrypted and its binary UPX-packed (T1027), reflecting a maintained, professionally engineered development effort well beyond what the group's 2023 campaign required. The final impact phase is where CyberAv3ngers most clearly diverges from typical eCrime or espionage actors: rather than exfiltrating data, the group erases or overwrites original PLC ladder logic with non-functional custom logic, changes device IP addresses and passwords specifically to lock legitimate operators out (as observed at scale in the July 2026 Minnesota campaign), and — per the 2026 Schneider/Siemens expansion — uploads malicious project files intended to override safety-critical control logic, a category of impact that moves beyond availability disruption into genuine physical-safety risk.

04
TTPs — MITRE ATT&CK Mapping Enterprise + ATT&CK for ICS — mapped against G1027
Reconnaissance
T1595.002
Active Scanning: Vulnerability Scanning
[HIGH] Shodan/Censys-style sweeps for internet-exposed Unitronics (TCP 20256) and Rockwell EtherNet/IP (TCP 44818) endpoints ahead of every observed campaign wave.
ATT&CK FOR ICS
Discovery
T0846
Remote System Discovery
[MEDIUM] Enumerates reachable PLC/HMI assets once initial access to one internet-exposed device is achieved.
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] Exploits CVE-2021-22681, an unpatched authentication-bypass flaw in Rockwell Automation Logix controllers, in the 2026 campaign (AA26-097A).
Initial Access
T1078.001
Valid Accounts: Default Accounts
[HIGH] Authenticated to Unitronics Vision Series PLCs/HMIs using the unmodified factory-default administrative password "1111" in the 2023 campaign.
Initial Access
T1133
External Remote Services
[HIGH] Relies on PLC/HMI management interfaces deployed directly on the public internet with no VPN or network segmentation.
Persistence
T1037.004
Boot or Logon Initialization Scripts: RC Scripts
[HIGH] IOCONTROL installs an rc.d boot script on compromised Linux-based OT/IoT devices to survive reboots.
Defense Evasion
T1027
Obfuscated Files or Information
[HIGH] IOCONTROL's configuration is AES-256-CBC encrypted and its binary UPX-packed to frustrate automated analysis and signature detection.
Command & Control
T1071
Application Layer Protocol
[HIGH] IOCONTROL C2 rides MQTT over TLS on port 8883, blending with legitimate IoT device telemetry.
Command & Control
T1071.004
Application Layer Protocol: DNS
[MEDIUM] Uses DNS-over-HTTPS for C2 domain resolution to defeat DNS-based blocking and monitoring.
ATT&CK FOR ICS
Inhibit Response Function
T0836
Modify Parameter
[HIGH] Remotely changed PLC IP addresses and passwords to lock legitimate operators out of Rockwell MicroLogix controllers across 30+ Minnesota utilities (Jul 2026).
ATT&CK FOR ICS
Impair Process Control
T0831
Manipulation of Control
[MEDIUM] Uploaded malicious project files to Schneider Electric and Siemens devices designed to override safety-critical control logic (2026 campaign).
ATT&CK FOR ICS
Inhibit Response Function
T0856
Spoof Reporting Message
[MEDIUM] Presented falsified process readings to operators while manipulating underlying device state, per 2026 reporting on Siemens/Schneider expansion.
ATT&CK FOR ICS
Impair Process Control
T0809
Data Destruction
[HIGH] Erased original Unitronics ladder-logic files and replaced them with non-functional custom logic during the 2023 campaign.
ATT&CK FOR ICS
Impact
T0813
Denial of Control
[HIGH] Triggered an alarm-driven booster-station shutdown at Aliquippa (2023) and broader loss of remote operator control across Minnesota utilities (2026).
Persistence / C2
T1219
Remote Access Tools
[HIGH] Deployed Dropbear SSH on victim cellular modems to establish remote access via port 22 (AA26-097A). Legitimate embedded software, so no malware signature exists to detect — and modems typically fall outside utility asset inventory and logging.
ATT&CK FOR ICS
Collection
T0845
Program Upload
[HIGH] Exfiltrated device project files (.ACD on Rockwell) from victim controllers using the vendors' own configuration software — Studio 5000 Logix Designer, EcoStruxure Control Expert, TIA Portal — run on leased third-party infrastructure (AA26-097A).
ATT&CK FOR ICS
Impact / Inhibit Response Function
T0889
Modify Program
[HIGH] "Modification and deletion of project file logic, to include Add-On Instructions (AOIs)" (AA26-097A). AOIs are reusable trusted code modules engineers rarely diff — the Jul 22 2026 advisory update added detection guidance specifically for anomalous AOI modification.
ATT&CK FOR ICS
Impact / Inhibit Response Function
T0878
Alarm Suppression
[HIGH] Modified project logic "disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators" (AA26-097A). The defining 2026 escalation over the group's 2023 defacement-grade activity.
ATT&CK FOR ICS
Impact
T0892
Change Credential
[HIGH] Remote PLC password changes locked legitimate operators out of their own controllers during the Jul 26–27 2026 disruption, directly forcing reversion to manual operation at multiple Minnesota utilities (Tenable; FBI WWS alert).
05
Targeting Profile
Sector Targeting
Water & Wastewater Systems
PRIMARY
Energy — Oil, Gas & Electricity
HIGH
Government Facilities
MED-HIGH
Fuel Management & Building Automation
MED
General Manufacturing / OT-Adjacent IoT
LOW
GeographiesPrimarily United States (dominant target since Nov 2023); Israel (original 2023 claims); United Kingdom and Ireland; confirmed intrusions across 7+ U.S. states as of Jul 2026
Victim ProfileSmall, rural, and municipal utilities with limited dedicated OT security budget and staffing; organizations running legacy or default-configured Unitronics, Rockwell/Allen-Bradley, Schneider Electric, or Siemens controllers
Preferred EntryDirectly internet-exposed PLC/HMI management interfaces (Shodan-discoverable); factory-default or hardcoded credentials; unpatched public CVEs in engineering-software-to-controller authentication (Rockwell CVE-2021-22681)
Target DoctrineOpportunistic scanning for exposed OT assets rather than pre-selected named victims — the group hits whatever internet-facing device of a targeted vendor family it can reach, then escalates from isolated incidents to coordinated, multi-victim bursts (30+ Minnesota utilities in a single 24-hour window)
06
Tools, Malware & Infrastructure
IOCONTROL Custom Linux OT/IoT Malware Platform
Modular, custom-built malware for Linux-based OT and IoT devices, attributed to CyberAv3ngers by Claroty Team82 (Dec 2024) after extraction from a compromised fuel management system. Targets routers, PLCs, HMIs, IP cameras, and firewalls from at least nine distinct vendors (Baicells, D-Link, Hikvision, Red Lion, Orpak, Phoenix Contact, Teltonika, Unitronics, and others). Communicates over MQTT/TLS (port 8883) to blend with legitimate IoT telemetry, resolves C2 domains via DNS-over-HTTPS, encrypts its configuration with AES-256-CBC, and is UPX-packed. Persists via an rc.d boot script stored as /usr/bin/iocontrol. Team82 characterizes it as a nation-state cyberweapon purpose-built to attack civilian critical infrastructure.
Custom Unitronics Ladder-Logic Payloads Bespoke ICS Logic Files
Device-model-specific ladder-logic files crafted to replace legitimate PLC control logic once default-credential administrative access is obtained on Unitronics Vision Series PLCs — the sole "payload" required for the 2023 campaign's impact phase, requiring no separate malware.
Rockwell Logix Authentication-Bypass Exploit Chain CVE-2021-22681 Weaponization
Leverages CVE-2021-22681, an insufficiently protected cryptographic key used to authenticate communications between Rockwell engineering software (Studio 5000 Logix Designer/RSLogix 5000) and Logix-family controllers, enabling unauthenticated remote connection, code upload, data download, and firmware manipulation. No vendor firmware patch is available as of this compile — the vulnerability has been public since 2021 (see vuln card: ROCKWELL-LOGIX-AUTH-BYPASS).
Shodan / Censys Reconnaissance OSINT / Commercial Scanning Services
Commercial internet-wide scanning platforms used to identify internet-exposed OT assets by default service port ahead of every observed campaign wave — not custom tooling, but a consistent and essential reconnaissance dependency.
Serial Telegram Persona Infrastructure Propaganda / Claim-of-Credit Channels
A sequence of disposable Telegram channels — CyberAv3ngers → "APT IRAN" → "Cyber4vengers" (Jan 2026) — used to claim credit, publish (sometimes fabricated or recycled) "proof" of compromise, and sustain the group's hacktivist narrative independent of and resilient to disruption of any single channel or persona.
Dropbear SSH Legitimate Embedded Software / Persistence
Lightweight open-source SSH server and client built for embedded Linux. Deployed by the group on victim cellular modems to establish remote access via port 22 (AA26-097A). Its operational value is precisely that it is not malware: it is plausible, common firmware-adjacent software that generates no signature-based detection, running on network equipment most water utilities neither inventory nor forward logs from. This converted opportunistic access to an exposed PLC into durable access to the site's communication path, independent of whether the controller itself was later hardened. Detection artifact: an SSH listener on a modem that has no operational reason to run one — not a file hash.
Vendor PLC Engineering Software Dual-Use / Living-off-the-Land (OT)
Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens Totally Integrated Automation (TIA) Portal — run by the actors on leased, third-party hosted infrastructure to connect to misconfigured victim PLCs and exfiltrate device project files (AA26-097A). This is living-off-the-land applied to OT: the traffic is the legitimate vendor engineering protocol carrying a legitimate engineering operation, indistinguishable from authorized integrator work absent a baseline recording who may upload or download a program and when. Possession of the project file — the plant's ladder logic and interlock configuration — is the prerequisite for the surgical safety-logic modification documented in the Jul 2026 advisory update (see incident card: 2026-07-26_US-WATER-SECTOR-PLC-CAMPAIGN).
07
Indicators of Compromise 21 static IPs published in AA26-097A; behavioral indicators remain the durable surface — see note below
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 13 are NOT defanged.
Type Value / Description Source Date
CVECVE-2021-22681 — Rockwell Automation Logix controllers authentication bypass via insufficiently protected cryptographic key; no firmware patch availableClaroty / CISA AA26-097A2026-04-07
CVECVE-2023-6448 / CVE-2023-6488 — Unitronics Vision Series PLC/HMI use of hard-coded default administrative credentials ("1111")CISA ICSA-23-348-152023-12
PORTTCP 20256 — default Unitronics Vision Series remote-access port; internet-facing exposure is the primary pre-condition for compromiseCISA AA23-335A2023-11
PORTTCP 44818 — Rockwell EtherNet/IP explicit messaging; scanned and targeted for direct controller access in the 2026 campaignCISA AA26-097A2026-04
PORTTCP/UDP 2222 — EtherNet/IP implicit (I/O) messaging; named alongside 44818 as a targeted OT portCISA AA26-097A2026-07
PORTTCP 102 — ISO-TSAP / S7 protocol; targeted on Siemens S7-1200 controllers after the Jul 2026 vendor-scope expansionCISA AA26-097A2026-07
PORTTCP 502 — Modbus; targeted on Schneider Electric Modicon M340 / BMX P34 controllersCISA AA26-097A2026-07
PORTTCP 22 — SSH on victim cellular modems via actor-deployed Dropbear; anomalous on a water-utility modem and a high-value detection pointCISA AA26-097A2026-07
PROTOCOLMQTT over TLS, destination port 8883 — IOCONTROL C2 channel; anomalous on most OT network segments and should be treated as a strong compromise indicatorClaroty Team822024-12
PROTOCOLDNS-over-HTTPS (DoH) traffic originating from OT/IoT network segments — used by IOCONTROL for C2 domain resolutionClaroty Team822024-12
FILE/usr/bin/iocontrol — IOCONTROL binary storage path on compromised Linux-based OT/IoT devices; rc.d boot script added for persistenceClaroty Team822024-12
IPV4185.82.73[.]175CISA AA26-097A Table 1 (22 Jul 2026)Sep 2025 – Feb 2026
IPV4141.11.164[.]153CISA AA26-097A Table 1 (22 Jul 2026)Jan 2026 – Jun 2026
IPV4175.110.121[.]39CISA AA26-097A Table 1 (22 Jul 2026)Feb 2026 – Mar 2026
IPV4175.110.121[.]41CISA AA26-097A Table 1 (22 Jul 2026)Feb 2026 – Mar 2026
IPV4175.110.121[.]42CISA AA26-097A Table 1 (22 Jul 2026)Feb 2026 – Mar 2026
IPV4175.110.121[.]107CISA AA26-097A Table 1 (22 Jul 2026)Feb 2026
IPV4192.142.54[.]79CISA AA26-097A Table 1 (22 Jul 2026)May 2026 – Jun 2026
IPV484.200.205[.]165CISA AA26-097A Table 1 (22 Jul 2026)May 2026 – Jun 2026
IPV4185.225.17[.]225CISA AA26-097A Table 1 (22 Jul 2026)Jun 2026 – Jul 2026
IPV479.133.46[.]209CISA AA26-097A Table 1 (22 Jul 2026)Jul 2026
IPV488.80.150[.]199CISA AA26-097A Table 1 (22 Jul 2026)Jul 2026
IPV488.80.150[.]200CISA AA26-097A Table 1 (22 Jul 2026)Jul 2026
IPV488.80.150[.]202CISA AA26-097A Table 1 (22 Jul 2026)Jul 2026
IPV4185.82.73[.]162CISA AA26-097A Table 2 (07 Apr 2026)Jan 2025 – Mar 2026
IPV4185.82.73[.]164CISA AA26-097A Table 2 (07 Apr 2026)Jan 2025 – Mar 2026
IPV4185.82.73[.]165CISA AA26-097A Table 2 (07 Apr 2026)Jan 2025 – Mar 2026
IPV4185.82.73[.]167CISA AA26-097A Table 2 (07 Apr 2026)Jan 2025 – Mar 2026
IPV4185.82.73[.]168CISA AA26-097A Table 2 (07 Apr 2026)Jan 2025 – Mar 2026
IPV4185.82.73[.]170CISA AA26-097A Table 2 (07 Apr 2026)Jan 2025 – Mar 2026
IPV4185.82.73[.]171CISA AA26-097A Table 2 (07 Apr 2026)Jan 2025 – Mar 2026
IPV4135.136.1[.]133CISA AA26-097A Table 2 (07 Apr 2026)Mar 2026
INFRALeased, third-party hosted infrastructure used to run vendor PLC programming software and to serve as the C2 channel for project-file transfer — not actor-owned bulletproof hosting in the classic senseCISA AA26-097A2025-01 – 2026-07
BEHAVIORUnauthorized PLC program upload or download outside a change window — vendor engineering protocol traffic from an IP that is not a known integrator or engineering workstationCISA AA26-097A detection guidance2026-07
BEHAVIORDivergence between running PLC logic and known-good baseline, with specific attention to modified or added Add-On Instructions (AOIs) on Rockwell controllersCISA AA26-097A (22 Jul 2026 update)2026-07
BEHAVIORController mode-switch state change to PROGRAM or REMOTE outside maintenance; ICS management protocol functions that change an asset's operating mode or modify programsCISA AA26-097A detection guidance2026-07
BEHAVIORUnexplained PLC credential change or device IP address reassignment resulting in operator lockout or loss of monitoringTenable; FBI WWS alert2026-07
NOTESuperseded as of 2026-09-12. The 2026-09-02 compile of this card stated that no durable, publicly attributed static IP list existed for this actor. That is no longer correct: AA26-097A published eight addresses on 2026-04-07 (Table 2) and thirteen more in its 2026-07-22 update (Table 1), all reproduced above. The earlier reasoning still holds in part — CyberAv3ngers' operational "infrastructure" is substantially the victim's own directly-exposed OT device rather than attacker-owned C2 hosting, and IOCONTROL's DoH/MQTT design resists static domain/IP enumeration — but static network IOCs now exist and should be hunted. Note that Table 2 addresses were published in April and may since have rotated. No file hashes, malware samples, C2 domains or YARA signatures have been published for the 2026 PLC campaign, which is consistent with tradecraft built on legitimate vendor engineering software, legitimate embedded SSH, and the victims' own project files rather than distributable malware. Behavioral and protocol indicators above, plus the TTPs in Section 04, remain the more durable detection surface.
08
Analyst Assessment
Overall Threat LevelCRITICAL
Attribution ConfidenceHIGH (state sponsorship) / MEDIUM (internal persona-vs-operator structure)
TrajectoryEscalating — from single-vendor default-credential abuse (2023) to a multi-vendor, safety-logic-targeting campaign disrupting 30+ utilities in one coordinated window (2026)
Most Dangerous CapabilityDemonstrated progression from availability-only disruption toward malicious project files designed to override safety-critical control logic — a genuine physical-safety risk category, not merely a nuisance-outage one
Primary Intel GapFull scope and formal government attribution of the Jul 2026 Minnesota/7-state campaign remains pending; true operational overlap between the propaganda-persona layer and IRGC-CEC technical operators is not fully resolved
Ecosystem / Affiliated Groups
Soldiers of Solomon IRGC-CEC Moses Staff Iranian State Cyber Apparatus

CyberAv3ngers occupies an unusually clear-cut position in the threat landscape: a state-directed actor whose sponsorship is not merely assessed but formally established through sanctions naming specific serving officers, operating with a public messaging apparatus that is transparently disposable and separable from its technical capability. That separation is itself analytically significant — takedowns of individual Telegram personas (the April 2024 disruption, the "APT IRAN" channel deletion) have consistently failed to reduce the group's underlying technical operational tempo, evidenced by the escalation straight through 2025 and into the 2026 Rockwell/Schneider/Siemens campaign. Any defensive or policy response premised on disrupting the persona layer alone should be understood as addressing symptom, not cause.

The single most consequential capability shift in this profile is the group's move, confirmed in the April 2026 AA26-097A advisory, from PLCs and ladder logic that merely stop functioning (denial of control, denial of view) to malicious project files on Schneider Electric and Siemens devices specifically engineered to override safety-critical logic and present operators with falsified process readings. That is a different risk category than an offline water pump: it describes the technical precondition for a scenario in which a facility's control system reports normal, safe operating parameters while the underlying physical process has been deliberately pushed outside safe bounds. No public reporting reviewed for this compile confirms such an outcome has yet occurred, and that gap should be stated plainly rather than implied — but the capability to attempt it is now documented, which was not true as recently as late 2023.

Competing hypotheses on intent persist and should inform, rather than be resolved by, this assessment: the group's activity is consistent with pure disruption/harassment (locking operators out, defacing HMI displays, generating propaganda material), with intelligence pre-positioning (maintaining latent access to U.S. critical infrastructure for use in a future crisis), or with both simultaneously as complementary lines of effort within the same IRGC-CEC unit. The July 2026 Minnesota campaign's tight, coordinated 24-hour timing across 30+ independently operated utilities argues for centralized, scripted state tasking rather than freelance or loosely coordinated hacktivist opportunism — a datapoint that should raise, not lower, confidence in the pre-positioning hypothesis. Confidence in the group's near-term trajectory would increase with formal government attribution of the Minnesota campaign (currently a vendor assessment, not an official one) and would be most significantly revised upward in severity by any confirmed instance of the safety-override capability actually being triggered against a live process.

09
Defensive Recommendations
01
Remove PLC/HMI management interfaces from direct internet exposure. Require VPN with MFA for any remote engineering or administrative access; treat any internet-reachable OT device found via Shodan/Censys-style sweep as an active incident precursor.
Counters: T1133, T1190, T1595.002
02
Change all default and factory-set credentials immediately upon device deployment — including the Unitronics "1111" administrative password — and enforce unique, strong, per-device credentials with regular rotation.
Counters: T1078.001
03
Apply Rockwell's compensating-control guidance for CVE-2021-22681 — CIP Security, IPsec, or equivalent communication-authentication hardening — since no firmware patch exists; segment engineering workstations from the broader network.
Counters: T1190
04
Deploy OT-aware network monitoring for MQTT-over-TLS (port 8883) and DNS-over-HTTPS traffic originating from OT segments — both are anomalous in well-segmented ICS environments not running IOCONTROL-family malware and are strong compromise indicators.
Counters: T1071, T1071.004
05
Maintain and regularly test offline, verified-clean backups of PLC ladder-logic and project files. Restoration must come from a trusted backup, not a live pull from an already-compromised device, following any Modify Parameter or Data Destruction event.
Counters: T0836, T0809
06
Implement independent, hard-wired safety instrumented systems (SIS) that cannot be reprogrammed via the same network path as the PLC/HMI. The 2026 campaign's demonstrated ability to override safety-critical logic in project files means software-only interlocks sharing the compromised network are insufficient.
Counters: T0831, T0856
07
Establish and drill manual/local operator override procedures and alarm-response training. This is precisely what prevented water-quality impact at both Aliquippa (2023) and across Minnesota (2026) — treat it as a proven, not theoretical, control.
Counters: T0813
08
Geofence and deny inbound traffic on known default OT ports (TCP 20256 for Unitronics, TCP 44818 for Rockwell EtherNet/IP) from non-whitelisted source ranges at the network perimeter.
Counters: T1133, T1595.002
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [HIGH]
The group treats its public-facing propaganda/claim-of-credit infrastructure as disposable and separable from technical operations: serial Telegram persona rebranding — CyberAv3ngers → "APT IRAN" → "Cyber4vengers" (Jan 2026) — has followed each platform-level takedown, with each new channel able to resume claim-of-credit activity without apparent loss of underlying technical capability. On the technical side, AA26-097A's two indicator tables now make rotation directly observable and supersede this card's 2026-09-02 assessment that no such reporting existed. The advisory describes leased, third-party hosted infrastructure — rented commodity hosting rather than attacker-owned servers — and the published addresses show a clear temporal cadence: a stable 185.82.73[.]0/24 cluster of seven addresses sustained from Jan 2025 through Mar 2026, then a shift to short-lived blocks held roughly one to two months each (175.110.121[.]x in Feb–Mar 2026; 192.142.54[.]79 and 84.200.205[.]165 in May–Jun; 185.225.17[.]225 in Jun–Jul), tightening to 88.80.150[.]199–202 and 79.133.46[.]209 within Jul 2026 alone. The pattern reads as a long-lived staging cluster during quiet pre-positioning, then accelerating rotation as operational tempo rose toward the July disruption. This remains distinct from classic implant C2: the leased nodes ran vendor PLC engineering software and carried project-file transfer, functioning as an operator workstation tier rather than a beacon C2 tier — consistent with the group's continued reliance on the victim's own exposed OT device as the actual foothold.
Living-off-the-Land Ratio [MEDIUM]
Shows a clear sophistication trend upward over time rather than a static ratio. The 2023 Unitronics campaign was almost entirely "living off default configuration" — no malware at all, just default-credential authentication followed by use of the PLC's own native ladder-logic upload feature. The 2024–2025 development of IOCONTROL introduced bespoke, purpose-built malware for OT/IoT persistence and C2, and the 2026 Rockwell/Schneider/Siemens campaign layers a CVE exploit on top of that. This progression — LOL-only to custom-tooled — is itself a useful maturity indicator for tracking the group's investment and resourcing over time.
Anti-Forensics [LOW-MEDIUM]
IOCONTROL's AES-256-CBC configuration encryption and UPX packing are best characterized as anti-analysis (frustrating malware researchers and automated detonation pipelines) rather than anti-forensics in the traditional log-clearing/timestomping sense. No public reporting reviewed for this compile documents the group clearing logs or manipulating timestamps on compromised OT devices specifically — a plausible and separate gap given how rarely PLCs and HMIs generate or retain rich forensic telemetry at all, which itself functions as a passive anti-forensics advantage the group does not need to actively engineer.
Timing & Operational Patterns [MEDIUM]
The July 2026 Minnesota campaign's tight coordination — 30+ independently operated municipal utilities affected within a roughly 24-hour window (Jul 26–27) — is a strong signal of centralized, scripted targeting rather than opportunistic, individually-timed intrusions. This is a departure from the more diffuse, rolling-disclosure pattern of the 2023–2024 wave (29 intrusions over roughly five months) and suggests the group's operational cadence has shifted toward deliberately synchronized, higher-impact bursts.
Tooling Hygiene [MEDIUM]
IOCONTROL's single-codebase, multi-vendor-device architecture — a modular design adapted across routers, PLCs, HMIs, IP cameras, and firewalls from at least nine distinct manufacturers — indicates a maintained, professionally engineered malware development effort consistent with dedicated state resourcing rather than ad hoc or one-off hacktivist tooling.
Personal & Identity OPSEC (Non-Technical) [MEDIUM]
Despite comparatively strong technical/malware tradecraft, the group's persona-management and communications layer has shown real operational security lapses: the April 2024 disruption of its Telegram communications is assessed by researchers as possibly linked to poor OPSEC that may have enabled geolocation of operators. This mirrors a pattern observed in other state-linked and eCrime persona-driven groups (see companion profile: LAPSUS$) where technical capability and personal/communications-layer discipline are not correlated.
11
Detection Evasion Specific techniques, protocol abuse, EDR/network bypass patterns
C2 Traffic Blending via MQTT-over-TLS T1071
NETWORK MQTT · Port 8883
IOCONTROL uses MQTT over TLS on port 8883 — a standard, widely-deployed IoT messaging protocol — for command-and-control, allowing its traffic to blend with legitimate device telemetry in OT/IoT environments where MQTT is common and rarely baselined or inspected by security monitoring (Claroty Team82).
Specific MQTT topic-naming scheme and broker infrastructure details not fully publicly documented as of 2026-09-02.
DNS-Based Detection Evasion via DNS-over-HTTPS T1071.004
NETWORK SIEM EVASION
IOCONTROL resolves C2 domains via DNS-over-HTTPS rather than conventional DNS, wrapping the resolution request inside ordinary HTTPS traffic to a public DoH resolver — defeating traditional DNS-monitoring, sinkholing, and domain-blocklist controls that inspect plaintext DNS queries.
Specific DoH resolver(s) used by the malware not publicly documented as of 2026-09-02.
Static Analysis Evasion via Packing & Config Encryption T1027
EDR BYPASS UPX · AES-256-CBC
IOCONTROL's binary is UPX-packed and its configuration block is AES-256-CBC encrypted, frustrating both automated malware-analysis sandboxes and simple string/signature-based detection — a defense-evasion investment that would be unnecessary for the group's earlier, malware-free 2023 campaign.
Encryption key management/derivation scheme not publicly documented as of 2026-09-02.
Detection-Surface Minimization via Native-Feature Abuse T1078.001
EDR BYPASS SIEM EVASION
The 2023 Unitronics campaign generated no malware signature at all: authenticating with unmodified default credentials and using the PLC's own legitimate ladder-logic upload feature meant every attacker action looked like ordinary authenticated administration. The primary "evasion" here is architectural — most OT devices of this class have no host-based security monitoring capable of distinguishing a legitimate admin login from an attacker one — rather than technical circumvention of a control that was never present.
No further technical specifics applicable — this technique's evasion value is structural, not procedural.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE CTID — NOT AVAILABLE No Adversary Emulation Plan Published
No MITRE Center for Threat-Informed Defense Full Emulation Plan has been published for CyberAv3ngers, IRGC-CEC, or G1027 as of 2026-09-02. The CTID Adversary Emulation Library's current Full Emulation Plans cover APT29, Blind Eagle, Carbanak Group, FIN6, FIN7, menuPass, OceanLotus, OilRig, Sandworm, Turla, and Wizard Spider — no ICS/OT-sabotage-focused Iranian state actor is represented in the library at this time.

Beyond CTID, no OT/ICS-specific Atomic Red Team tests or Sigma detection rules mapped directly to CyberAv3ngers' PLC-manipulation techniques (ATT&CK for ICS T0836, T0831, T0856, T0809, T0813) were identified as published during this compile — these techniques describe device-specific control-logic manipulation that general-purpose Windows/Linux-oriented detection-content repositories do not typically cover. The most directly applicable published purple-team resources are the detection and indicator guidance embedded in the CISA/FBI joint advisories themselves (AA23-335A, AA26-097A) and Claroty Team82's IOCONTROL technical report, both of which include protocol- and behavior-level detection guidance referenced in Sections 07 and 11 above. Organizations building a purple-team program against this actor should treat those advisories, plus Dragos's and Claroty's OT-specific threat-hunting guidance, as the primary available emulation and detection references rather than relying on general enterprise-IT detection-content libraries, which currently have no CyberAv3ngers-specific coverage.

13
References URLs are NOT defanged — navigate directly
MITRE ATT&CK
Accessed: 2026-09-02
Claroty Team82
Accessed: 2026-09-02
Claroty Team82
Accessed: 2026-09-02
Secureworks
Accessed: 2026-09-02
Wikipedia (secondary, corroborating)
Accessed: 2026-09-02
SecurityWeek / mbtmag
Accessed: 2026-09-02
CISA / FBI / NSA / EPA / DOE / CNMF / TREASURY — 2026-09-12 REFRESH
AA26-097A — Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure (pub. 7 Apr 2026, upd. 22 Jul 2026) — Source for Table 1 / Table 2 IP indicators, Dropbear SSH, vendor engineering-software abuse, and AOI modification detection guidance.
Accessed: 2026-09-12
CYBERSECURITY DIVE — 2026-09-12 REFRESH
What we know so far about the hacking campaign against US water systems — Source for 12-state scope and the APT Iran claim of responsibility via Check Point Research.
Accessed: 2026-09-12
MINNESOTA IT SERVICES — 2026-09-12 REFRESH
Accessed: 2026-09-12
CSIS — 2026-09-12 REFRESH
Mapping Iranian Cyberattacks on U.S. Water Systems — Source for the 100+ targeted facilities figure.
Accessed: 2026-09-12