Cyber overview
Cyber threat actor

CyberAv3ngers

Iranian state-sponsored (IRGC Cyber-Electronic Command linked) · active since 2020

Hacktivist-branded persona conducting operations against Israeli and US industrial control systems, notably exploiting default credentials on water-utility programmable logic controllers.

Aliases
IRGC-CEC affiliated
Primary targets
Water utilities Industrial control systems Unitronics PLCs

MITRE ATT&CK techniques

0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

No MITRE ATT&CK mapping available yet for CyberAv3ngers.

Curated incidents

  1. 2023-12-01·Water·United States
    CyberAv3ngers exploit Unitronics PLCs at US water utility

    Municipal water authority in Pennsylvania has a booster station PLC defaced after default-credential exploitation.

Live feed mentions
  1. Fri, 01 Dec 2023 14:00:00 GMT · CISA / FBI / NSA advisory AA23-335A
    Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities