operational Threat Intelligencehigh

Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities

Fri, Dec 1, 2023, 02:00 PM UTC·Dec 1, 2023· Adversary: Iran (ADV-IR)

Summary

Bottom line: Iranian Government Islamic Revolutionary Guard Corps affiliated actors defaced and disrupted programmable logic controllers at small water systems using default credentials on internet-exposed devices. Change default passwords and remove operational technology from the public internet as the first control.

Key claims· extracted from reporting

  • Bottom line: Iranian Government Islamic Revolutionary Guard Corps affiliated actors defaced and disrupted programmable logic controllers at small water systems using default credentials on internet-exposed devices.Low · 10%
    named entity×3
  • Change default passwords and remove operational technology from the public internet as the first control.Low · 10%
    named entity

Heuristic extraction, verify against the original report before citing.

Tags· click to alert

Key takeaways

The three things worth remembering from this item.

  1. 1Bottom line: Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities[1]
  2. 2CyberAv3ngers activity is the driver here, and the objective is what should shape your response, not the tool names.[1][2]
  3. 3Defensively, the highest-leverage move is coverage for T1078 · Valid Accounts, because it is a behavior class rather than an indicator.[1][2]

Concepts in this story

Each concept opens in layers: plain English, technical, then expert.

CyberAv3ngers

Iran · Moderate tempo

CyberAv3ngers is a Iran linked hacking group. In plain terms, they break into water utilities, industrial control systems, unitronics plcs and stay there. Their goal is to symbolic ot disruption at small us utilities.

Why it matters
Iranian activity is opportunistic and symbolic, often hitting small utilities and civil society targets that lack dedicated security staff.[1][2]
Common misconception
That low sophistication means low impact. Default credentials on an internet-exposed controller are enough to affect a real utility.
Cyber Kill ChainNIST CSF 2.0, Identify, Detect, Respond
Sources for this concept
  1. [1]CyberAv3ngers exploit Unitronics PLCs at US water utility· Public incident reporting· 2023-12-01 00:00Z
  2. [2]Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities· CISA / FBI / NSA advisory AA23-335A· 2023-12-01 14:00Z

T1078 · Valid Accounts

Initial Access · used by 18 tracked groups

Valid Accounts is how an attacker initial access works in practice. Stolen or sprayed credentials used in place of malware, defeating signature-based detection.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1078 Tactic: Initial Access
Sources for this concept
  1. [1]T1078 · Valid Accounts· MITRE ATT&CK T1078
  2. [2]Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities· CISA / FBI / NSA advisory AA23-335A· 2023-12-01 14:00Z

T1190 · Exploit Public-Facing Application

Initial Access · used by 13 tracked groups

Exploit Public-Facing Application is how an attacker initial access works in practice. Edge devices and VPN appliances (Ivanti, Fortinet, Citrix, Cisco) exploited within hours of CVE disclosure.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1190 Tactic: Initial Access
Sources for this concept
  1. [1]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190
  2. [2]Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities· CISA / FBI / NSA advisory AA23-335A· 2023-12-01 14:00Z

T1499 · Endpoint Denial of Service

Impact · used by 4 tracked groups

Endpoint Denial of Service is how an attacker impact works in practice. Disruption of operational technology and public-facing services.

Why it matters
This is a impact behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1499 Tactic: Impact
Sources for this concept
  1. [1]T1499 · Endpoint Denial of Service· MITRE ATT&CK T1499
  2. [2]Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities· CISA / FBI / NSA advisory AA23-335A· 2023-12-01 14:00Z
Sources for these takeaways
  1. [1]Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities· CISA / FBI / NSA advisory AA23-335A· 2023-12-01 14:00Z
  2. [2]CyberAv3ngers exploit Unitronics PLCs at US water utility· Public incident reporting· 2023-12-01 00:00Z
  3. [3]T1078 · Valid Accounts· MITRE ATT&CK T1078

Related concepts

Threads that build naturally on what you just read.

T1078 · Valid AccountsInitial AccessT1190 · Exploit Public-Facing ApplicationInitial AccessT1499 · Endpoint Denial of ServiceImpact
Cyber Kill ChainSequence model behind the attack chain diagram
NIST CSF 2.0Govern, Identify, Protect, Detect, Respond, Recover

Knowledge check

Five questions. Answers explain the reasoning, not just the result.

Question 1 of 5

Which nexus is CyberAv3ngers attributed to in public reporting?

Question 2 of 5

Which sector is a primary target for CyberAv3ngers?

Question 3 of 5

Which ATT&CK tactic does T1078 (Valid Accounts) belong to?

Question 4 of 5

Which ATT&CK tactic does T1190 (Exploit Public-Facing Application) belong to?

Question 5 of 5

Which ATT&CK tactic does T1499 (Endpoint Denial of Service) belong to?

Answer all 5 to check.
Estimated mastery
First time on this material.
New · 0/100