Home/Threat Actor/BAUXITE
Threat Actor

BAUXITE

bauxite · iran_linked_dragos_tracked_ics_activity_group_cyberav3ngers_persona_2024_disclosed · active since 2023-01

BAUXITE is Dragos's tracked Iran-linked Activity Group designation disclosed in Dragos 2024 Year- in-Review report operating under the CyberAv3ngers hacktivist persona with ICS Cyber Kill Chain Stage 2 capability (alongside CHERNOVITE + VOLTZITE + ELECTRUM elite cluster category) per SecurityWeek canonical Nine Threat Groups Active in OT Operations in 2024 Dragos coverage ("One of them has been named Bauxite, which has been linked to Iran. Operating under the hacktivist persona CyberAv3ngers, Bauxite has targeted organizations in the US, Europe, Australia and the Middle East, including sectors such as energy, water, food and beverage, and chemical manufacturing. The hackers were recently seen using a custom-built malware named IOCONTROL to target IoT and OT devices in the US and Israel")

Iran-linked attribution per Dragos canonical 2024 Year-in-Review disclosure (more specific than typical Dragos no-public-nation- attribution policy due to CyberAv3ngers public Iranian state-affiliated activity) + SecurityWeek Nine Threat Groups Active coverage + Enterprise Times 2025 Dragos says 2024 lowered the barrier for OT/ICS attacks 100%-internet-accessible- target signature coverage + Dragos 2025 OT Cybersecurity Year in Review continued tracking + Dragos MITRE ATT&CK for ICS framework taxonomy listing.

honest attribution caveat: BAUXITE operationally overlaps with already-curated cyberav3ngers cluster in corpus, Dragos tracks BAUXITE as distinct ICS-focused Stage 2 capability cluster based on Dragos taxonomy methodology parallel to KAMACITE/Sandworm + COVELLITE/Lazarus methodology precedent established in v0.1.166; Iran-attribution is more specific than typical Dragos disclosure due to CyberAv3ngers persona's public Iranian state-affiliated activity in post- October-2023 Israel-Hamas war targeting expansion.

standalone cluster paralleling laurionite + gananite + kostovite in v0.1.172 OT/ICS Dragos-newer-taxonomy actor cluster cell continuation.

operational target profile signature US + Israel + Europe + Australia + Middle East geographic distribution per Dragos + signature energy + water + food and beverage + chemical manufacturing multi-sector targeting + cluster-defining 100% internet-accessible targets per Enterprise Times Dragos 2024 + signature Unitronics Vision PLCs at water utilities (e.g. Aliquippa PA + Israeli targets) using default credentials + open-internet-accessible configurations.

operational attack architecture: (1) cluster-defining Iran-linked attribution per Dragos canonical 2024 disclosure with more- specific-than-typical attribution policy due to CyberAv3ngers public Iranian affiliation.

(2) cluster-defining CyberAv3ngers hacktivist persona operating with hacktivist-persona-as- cover for state-aligned ICS targeting operations; (3) cluster-defining IOCONTROL custom-built malware targeting IoT and OT devices in the US and Israel per SecurityWeek + Dragos 2024 disclosure.

(4) cluster-defining ICS Cyber Kill Chain Stage 2 capability designation placing BAUXITE among elite Dragos-tracked clusters (4 total: BAUXITE + CHERNOVITE + VOLTZITE + ELECTRUM) capable of developing + testing specific and meaningful attacks on industrial control systems.

(5) cluster-defining 100% internet-accessible target operational signature per Enterprise Times 2025 Dragos report ("New threat actor Bauxite feeds off this lack of defence. 100% of its targets were accessible from the Internet")

(6) cluster-defining VPN + firewall + PLC SSH brute force tradecraft per Enterprise Times Dragos coverage ("This includes the compromise of VPNs, firewalls and PLCs using brute force SSH attacks")

(7) cluster-defining Unitronics Vision PLC water utility 2023-2024 campaign signature with default credentials (1111) exploitation + Aliquippa PA + Israeli water targets establishing operational precedent for BAUXITE tracking.

(8) signature post-October 2023 Israel-Hamas war targeting expansion with Iran-affiliated state- aligned operational signatures becoming more prominent + campaign tempo increase.

(9) signature multi-sector energy + water + food and beverage + chemical manufacturing targeting reflecting broad critical-infrastructure objectives.

(10) signature Dragos 2025 OT Cybersecurity Year in Review continued tracking establishing operational continuity + active-tracking-status.

(11) signature Dragos MITRE ATT&CK for ICS framework taxonomy listing establishing reference-status alongside other Dragos-tracked clusters; cluster fills the Dragos-BAUXITE-Activity-Group + Iran-linked-attribution + CyberAv3ngers-hacktivist- persona-operating + IOCONTROL-custom-malware-IoT- OT-targeting + US-Europe-Australia-Middle-East- targeting + energy-water-food-beverage-chemical- manufacturing-multi-sector + ICS-Cyber-Kill- Chain-Stage-2-capability + 100-percent-internet- accessible-target-signature + VPN-firewall-PLC- SSH-brute-force + Unitronics-PLC-campaign- signature + 2024-Dragos-Year-in-Review-disclosure position in OT/ICS Dragos-newer-taxonomy actor cluster cell.

canonical illustration of Iran- linked ICS Activity Group + hacktivist-persona- as-cover for state-aligned operations + IOCONTROL custom malware + 100%-internet-accessible-target + VPN/firewall/PLC SSH brute force tradecraft + ICS Cyber Kill Chain Stage 2 capability alongside CHERNOVITE + VOLTZITE + ELECTRUM elite cluster category methodology cited in essentially all subsequent Iran-attributed ICS-targeting industry analyses through 2024-2026 period.

iran_linked_dragos_tracked_ics_activity_group_cyberav3ngers_persona_2024_disclosed confidence: high 15 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

BAUXITE is Dragos's tracked Iran-linked Activity Group designation disclosed in Dragos 2024 Year- in-Review report operating under the CyberAv3ngers hacktivist persona with ICS Cyber Kill Chain Stage 2 capability (alongside CHERNOVITE + VOLTZITE + ELECTRUM elite cluster category). Iran-linked attribution per Dragos canonical 2024 Year-in-Review disclosure (more specific than typical Dragos no-public-nation-attribution policy due to CyberAv3ngers public Iranian affiliation) + SecurityWeek + Enterprise Times industry coverage. Honest attribution caveat: BAUXITE operationally overlaps with already-curated cyberav3ngers cluster in corpus.

Dragos tracks BAUXITE as distinct ICS-focused Stage 2 capability cluster based on Dragos taxonomy methodology, parallel to KAMACITE/Sandworm + COVELLITE/Lazarus methodology precedent established in v0.1.166. Standalone cluster paralleling laurionite + gananite + kostovite in v0.1.172 OT/ICS Dragos- newer-taxonomy actor cluster cell continuation.

Operational target profile
  • US + Israel + Europe + Australia + Middle East signature.
  • Energy + water + food and beverage + chemical manufacturing signature sectors.
  • 100% internet-accessible targets distinctive operational pattern.
  • IoT + OT devices specifically (Unitronics PLCs + similar) Operational attack architecture: (1) Iran-linked attribution (cluster-defining) (2) CyberAv3ngers hacktivist persona operating (cluster-defining) (3) IOCONTROL custom malware US+Israel IoT/OT targeting (cluster-defining) (4) ICS Cyber Kill Chain Stage 2 capability (cluster-defining) (5) 100% internet-accessible target operational signature (cluster-defining) (6) VPN + firewall + PLC SSH brute force tradecraft (cluster-defining) (7) Unitronics PLC campaign signature (cluster- defining) The cluster fills the Dragos-BAUXITE-Activity- Group + Iran-linked-attribution + CyberAv3ngers- hacktivist-persona-operating + IOCONTROL-custom- malware-IoT-OT-targeting + US-Europe-Australia- Middle-East-targeting + energy-water-food- beverage-chemical-manufacturing-multi-sector + ICS-Cyber-Kill-Chain-Stage-2-capability + 100- percent-internet-accessible-target-signature + VPN-firewall-PLC-SSH-brute-force + Unitronics- PLC-campaign-signature + 2024-Dragos-Year-in- Review-disclosure position in OT/ICS Dragos- newer-taxonomy actor cluster cell.

Aliases

15
bauxitebauxite activity groupdragos bauxite trackingbauxite iran-linked ics activity groupbauxite cyberav3ngers hacktivist persona operating signaturebauxite iocontrol custom malware iot ot targetingbauxite us energy water food beverage chemical manufacturingbauxite europe australia middle east targetingbauxite ics cyber kill chain stage 2 capabilitybauxite 2024 dragos year-in-review disclosurebauxite internet-accessible target 100 percent signaturebauxite vpn firewall plc ssh brute forcebauxite unitronics plc 2023 2024 attacks signaturebauxite iran irgc israel us israel targetingbauxite distinct from cyberav3ngers dragos ics-focused methodology

Notable Campaigns

9
2025BAUXITE 2025 Dragos Continued Tracking Signature
2024-2026Continued Industry Reference Status (2024-2026)
2024BAUXITE Dragos 2024 Year-in-Review Disclosure with Iran Linkage
2024BAUXITE IOCONTROL Custom Malware US + Israel IoT/OT Targeting Signature
2024BAUXITE ICS Cyber Kill Chain Stage 2 Capability Signature
2024BAUXITE 100% Internet-Accessible Target Operational Signature
2023-2024BAUXITE CyberAv3ngers Hacktivist Persona Operating Signature
2023-2024BAUXITE Unitronics PLC 2023-2024 Water Utility Attack Campaign Signature
2023-2024BAUXITE Post-October 2023 Israel-Hamas War Targeting Expansion Signature

Attribution & Reporting

Attributed by
Dragos (canonical BAUXITE Activity Group designation 2024 Year-in-Review + Iran-linkage acknowledgment)SecurityWeek (canonical Nine Threat Groups Active in OT Operations 2024 coverage)Enterprise Times / Ian Murphy (canonical Dragos 2024 lowered the barrier for OT/ICS attacks coverage)Dragos 2025 OT Cybersecurity Year in Review (canonical tracking continuation)Dragos MITRE ATT&CK for ICS framework documentation (canonical taxonomy listing)
Key reporting
reportDragos (2024): canonical BAUXITE Activity Group designation 2024 Year-in-Review with Iran-linkage
reportSecurityWeek: Nine Threat Groups Active in OT Operations in 2024, canonical coverage
reportEnterprise Times / Ian Murphy: Dragos says 2024 lowered the barrier for OT/ICS attacks, canonical 100% internet-accessible signature
reportDragos (2025): 2025 OT Cybersecurity Year in Review continued tracking
reportDragos MITRE ATT&CK for ICS framework: canonical taxonomy listing

Operational

State sponsor

BAUXITE is Dragos's tracked Iran-linked Activity Group designation disclosed in Dragos 2024 Year- in-Review report assessed with ICS Cyber Kill Chain Stage 2 capability. Per SecurityWeek covering Dragos: "One of them has been named Bauxite, which has been linked to Iran. Operating under the hacktivist persona CyberAv3ngers, Bauxite has targeted organizations in the US, Europe, Australia and the Middle East, including sectors such as energy, water, food and beverage, and chemical manufacturing.

The hackers were recently seen using a custom-built malware named IOCONTROL to target IoT and OT devices in the US and Israel." Honest attribution caveat: BAUXITE operationally overlaps with the already-curated cyberav3ngers cluster in corpus. Dragos tracks BAUXITE as distinct ICS-focused Stage 2 capability cluster based on Dragos taxonomy methodology, parallel to KAMACITE/Sandworm + COVELLITE/Lazarus methodology precedent established in v0.1.166. Iran-attribution is more specific than typical Dragos disclosure (Dragos doesn't usually publicly attribute to nations, but Iran-linkage was acknowledged for BAUXITE due to CyberAv3ngers persona's public Iranian state-affiliated activity).

Attribution chain: (1) SecurityWeek + Dragos canonical 2024 Year- in-Review BAUXITE disclosure with Iran linkage: per SecurityWeek covering Dragos: "Two of them are newly added groups. One of them has been named Bauxite, which has been linked to Iran. Operating under the hacktivist persona CyberAv3ngers, Bauxite has targeted organizations in the US, Europe, Australia and the Middle East, including sectors such as energy, water, food and beverage, and chemical manufacturing." (2) IOCONTROL custom malware signature: per SecurityWeek: "The hackers were recently seen using a custom-built malware named IOCONTROL to target IoT and OT devices in the US and Israel." Cluster-defining custom-malware tradecraft distinguishing BAUXITE from open-source-tooling- focused clusters like LAURIONITE.

(3) ICS Cyber Kill Chain Stage 2 capability assessment: per SecurityWeek: "Of the nine groups that were active in OT operations in 2024, four are known to have ICS Cyber Kill Chain Stage 2 capabilities, which indicates that they can develop and test specific and meaningful attacks on industrial control systems. In addition to Bauxite, the list of groups with Stage 2 capabilities includes Chernovite (the group behind the Pipedream/Incontroller attack), Voltzite (aka Volt Typhoon, which exfiltrated sensitive OT data), and Electrum (aka Sandworm, which developed a new wiper capability named AcidPour)." Cluster-defining Stage 2 capability assessment placing BAUXITE among elite Dragos- tracked clusters. (4) Enterprise Times 2025 Dragos 2024 report 100%-internet-accessible-target signature: per Enterprise Times: "New threat actor Bauxite feeds off this lack of defence. 100% of its targets were accessible from the Internet.

This includes the compromise of VPNs, firewalls and PLCs using brute force SSH attacks. Organisations need to rethink how they spot such attacks and make sure they keep on top of alerts and patching." Cluster-defining 100%-internet-accessible-target operational signature + VPN + firewall + PLC SSH brute force tradecraft.

Operational target profile
  • US signature per Dragos.
  • Europe signature per Dragos.
  • Australia signature per Dragos.
  • Middle East signature per Dragos (includes Israel)
  • Energy sector signature.
  • Water sector signature.
  • Food and beverage sector signature.
  • Chemical manufacturing sector signature.
  • 100% internet-accessible targets per Dragos 2024, distinctive operational pattern.
  • IoT + OT devices specifically (Unitronics PLCs + similar) The cluster fills the Dragos-BAUXITE-Activity- Group + Iran-linked-attribution + CyberAv3ngers- hacktivist-persona-operating + IOCONTROL-custom- malware-IoT-OT-targeting + US-Europe-Australia- Middle-East-targeting + energy-water-food- beverage-chemical-manufacturing-multi-sector + ICS-Cyber-Kill-Chain-Stage-2-capability + 100- percent-internet-accessible-target-signature + VPN-firewall-PLC-SSH-brute-force + Unitronics- PLC-campaign-signature + 2024-Dragos-Year-in- Review-disclosure position in OT/ICS Dragos- newer-taxonomy actor cluster cell.
Motivations
iran_linked_state_actor_dragos_tracked_ics_focused, cyberav3ngers_hacktivist_persona_operating_signature, iocontrol_custom_malware_iot_ot_device_targeting, ics_cyber_kill_chain_stage_2_capability_signature, 100_percent_internet_accessible_target_operational_signature, us_israel_geopolitical_targeting_iranian_alignment
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)43/60 · 71%
Analytics (MITRE CAR)26/60 · 43%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin