BAUXITE
BAUXITE is Dragos's tracked Iran-linked Activity Group designation disclosed in Dragos 2024 Year- in-Review report operating under the CyberAv3ngers hacktivist persona with ICS Cyber Kill Chain Stage 2 capability (alongside CHERNOVITE + VOLTZITE + ELECTRUM elite cluster category) per SecurityWeek canonical Nine Threat Groups Active in OT Operations in 2024 Dragos coverage ("One of them has been named Bauxite, which has been linked to Iran. Operating under the hacktivist persona CyberAv3ngers, Bauxite has targeted organizations in the US, Europe, Australia and the Middle East, including sectors such as energy, water, food and beverage, and chemical manufacturing. The hackers were recently seen using a custom-built malware named IOCONTROL to target IoT and OT devices in the US and Israel")
Iran-linked attribution per Dragos canonical 2024 Year-in-Review disclosure (more specific than typical Dragos no-public-nation- attribution policy due to CyberAv3ngers public Iranian state-affiliated activity) + SecurityWeek Nine Threat Groups Active coverage + Enterprise Times 2025 Dragos says 2024 lowered the barrier for OT/ICS attacks 100%-internet-accessible- target signature coverage + Dragos 2025 OT Cybersecurity Year in Review continued tracking + Dragos MITRE ATT&CK for ICS framework taxonomy listing.
honest attribution caveat: BAUXITE operationally overlaps with already-curated cyberav3ngers cluster in corpus, Dragos tracks BAUXITE as distinct ICS-focused Stage 2 capability cluster based on Dragos taxonomy methodology parallel to KAMACITE/Sandworm + COVELLITE/Lazarus methodology precedent established in v0.1.166; Iran-attribution is more specific than typical Dragos disclosure due to CyberAv3ngers persona's public Iranian state-affiliated activity in post- October-2023 Israel-Hamas war targeting expansion.
standalone cluster paralleling laurionite + gananite + kostovite in v0.1.172 OT/ICS Dragos-newer-taxonomy actor cluster cell continuation.
operational target profile signature US + Israel + Europe + Australia + Middle East geographic distribution per Dragos + signature energy + water + food and beverage + chemical manufacturing multi-sector targeting + cluster-defining 100% internet-accessible targets per Enterprise Times Dragos 2024 + signature Unitronics Vision PLCs at water utilities (e.g. Aliquippa PA + Israeli targets) using default credentials + open-internet-accessible configurations.
operational attack architecture: (1) cluster-defining Iran-linked attribution per Dragos canonical 2024 disclosure with more- specific-than-typical attribution policy due to CyberAv3ngers public Iranian affiliation.
(2) cluster-defining CyberAv3ngers hacktivist persona operating with hacktivist-persona-as- cover for state-aligned ICS targeting operations; (3) cluster-defining IOCONTROL custom-built malware targeting IoT and OT devices in the US and Israel per SecurityWeek + Dragos 2024 disclosure.
(4) cluster-defining ICS Cyber Kill Chain Stage 2 capability designation placing BAUXITE among elite Dragos-tracked clusters (4 total: BAUXITE + CHERNOVITE + VOLTZITE + ELECTRUM) capable of developing + testing specific and meaningful attacks on industrial control systems.
(5) cluster-defining 100% internet-accessible target operational signature per Enterprise Times 2025 Dragos report ("New threat actor Bauxite feeds off this lack of defence. 100% of its targets were accessible from the Internet")
(6) cluster-defining VPN + firewall + PLC SSH brute force tradecraft per Enterprise Times Dragos coverage ("This includes the compromise of VPNs, firewalls and PLCs using brute force SSH attacks")
(7) cluster-defining Unitronics Vision PLC water utility 2023-2024 campaign signature with default credentials (1111) exploitation + Aliquippa PA + Israeli water targets establishing operational precedent for BAUXITE tracking.
(8) signature post-October 2023 Israel-Hamas war targeting expansion with Iran-affiliated state- aligned operational signatures becoming more prominent + campaign tempo increase.
(9) signature multi-sector energy + water + food and beverage + chemical manufacturing targeting reflecting broad critical-infrastructure objectives.
(10) signature Dragos 2025 OT Cybersecurity Year in Review continued tracking establishing operational continuity + active-tracking-status.
(11) signature Dragos MITRE ATT&CK for ICS framework taxonomy listing establishing reference-status alongside other Dragos-tracked clusters; cluster fills the Dragos-BAUXITE-Activity-Group + Iran-linked-attribution + CyberAv3ngers-hacktivist- persona-operating + IOCONTROL-custom-malware-IoT- OT-targeting + US-Europe-Australia-Middle-East- targeting + energy-water-food-beverage-chemical- manufacturing-multi-sector + ICS-Cyber-Kill- Chain-Stage-2-capability + 100-percent-internet- accessible-target-signature + VPN-firewall-PLC- SSH-brute-force + Unitronics-PLC-campaign- signature + 2024-Dragos-Year-in-Review-disclosure position in OT/ICS Dragos-newer-taxonomy actor cluster cell.
canonical illustration of Iran- linked ICS Activity Group + hacktivist-persona- as-cover for state-aligned operations + IOCONTROL custom malware + 100%-internet-accessible-target + VPN/firewall/PLC SSH brute force tradecraft + ICS Cyber Kill Chain Stage 2 capability alongside CHERNOVITE + VOLTZITE + ELECTRUM elite cluster category methodology cited in essentially all subsequent Iran-attributed ICS-targeting industry analyses through 2024-2026 period.