Home/Threat Actor/CyberAv3ngers (IRGC-CEC)
Threat Actor

CyberAv3ngers (IRGC-CEC)

cyberav3ngers · iran · active since 2020

CyberAv3ngers (canonical hacktivist-style persona naming; CISA canonical Shahid Kaveh Group naming for the IRGC-CEC unit per April 2026 advisory.

Microsoft Storm-0784.

Mandiant UNC5691.

CrowdStrike Hydro Kitten) is an Islamic Republic of Iran state actor formally attributed by US CISA / FBI / NSA / EPA / Israel National Cyber Directorate to the Iranian Government Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC), one of the few publicly-attributed Iran-aligned clusters with formal government attribution at the named-unit level.

operates the CyberAv3ngers hacktivist- style public persona with Persian-language Telegram channel claiming responsibility for attacks accompanied by Israeli- themed defacement messaging ("You have been hacked, down with Israel. Every equipment 'made in Israel' is CyberAv3ngers legal target.")

signature operational tradecraft includes internet-exposed Unitronics Vision Series PLC factory-default- credential exploitation, PLC ladder logic upload + HMI defacement, Israeli-made-equipment-specific targeting regardless of victim geography, IRGC-aligned operational pattern similar to SecureWorks COBALT SAPLING operating Moses Staff and Abraham's Ax personas.

canonical operations include February 2022 Israel E-Post Unitronics compromises, April 2023 Israel agricultural irrigation cyberattack, November 25, 2023 Municipal Water Authority of Aliquippa Pennsylvania compromise (first US facility target, triggered December 1, 2023 CISA Joint Advisory AA23-335A establishing formal IRGC-CEC attribution), and multi-state US water facilities campaign November 2023 - January 2024 (~75 Unitronics PLCs across US/UK/Ireland in four waves); February 2024 US Treasury sanctions against six IRGC-CEC officials + State Department Rewards for Justice $10M bounty.

mid-2024 Claroty Team82 disclosure of custom IOCONTROL Linux malware platform for IoT/OT environments with MQTT-over-TLS C2 communication.

tradecraft proliferation across ~60 affiliated hacktivist groups.

April 2026 CISA AA26-097A follow-up advisory with Shahid Kaveh Group naming; fills IRGC-CEC-attributed Iran-aligned APT cell with ICS/OT- specific targeting focus complementing existing 8 Iran- aligned clusters in the curated corpus.

iran confidence: high 19 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited3

Profile

CyberAv3ngers (canonical hacktivist-style persona naming; CISA canonical "Shahid Kaveh Group" naming for the IRGC-CEC unit per April 2026 advisory.

Microsoft Storm-0784.

Mandiant UNC5691.

CrowdStrike Hydro Kitten) is an Islamic Republic of Iran state actor operationally attributed by the US CISA, FBI, NSA, EPA, and Israel National Cyber Directorate to the Iranian Government Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC), operationally one of the few publicly-attributed Iran-aligned clusters with formal government attribution to a specific Iranian government agency at the named-unit level, distinguishing the cluster from broader "Iran-aligned" attribution categories applied to most other Iran-aligned clusters. The cluster operationally uses the "CyberAv3ngers" hacktivist- style public persona, a Persian-language Telegram channel claiming responsibility for attacks accompanied by defacement images stating "You have been hacked, down with Israel. Every equipment 'made in Israel' is CyberAv3ngers legal target." SecureWorks Counter Threat Unit assesses that "Cyber Av3ngers is operated by an Iranian state-sponsored threat group in the same way that COBALT SAPLING operates the Moses Staff and Abraham's Ax personas", operationally consistent with the broader IRGC pattern of operating state- sponsored cyber operations under hacktivist-style cover personas. Operational phases of the cluster's longitudinal history: (1) ISRAEL-FOCUSED OPERATIONAL EMERGENCE (2020-October 2023). Earliest CISA-documented activity dates to 2020. Operations focused on Israeli infrastructure including February 2022 E-Post Unitronics compromises (postbox systems in two Israeli cities), April 2023 agricultural irrigation cyberattack against farms in northern Israel (ten water controllers), and October 2023 surge of Israel-based PLC attacks coinciding with the post-October-7 Israel-Hamas conflict escalation.

(2) US WATER FACILITIES CAMPAIGN AND ALIQUIPPA ESCALATION (November 22, 2023
  • January 2024). Operational pivot to US- based targeting. November 25, 2023 Municipal Water Authority of Aliquippa Pennsylvania compromise operationally consequential as the first publicly-confirmed CyberAv3ngers attack on a US facility, triggering the December 1, 2023 CISA/FBI/NSA/EPA/Israeli joint advisory establishing formal IRGC-CEC government attribution. Approximately 75 Unitronics PLCs compromised across US, UK, and Ireland in four waves between November 2023 and January 2024 per Tenable analysis. (3) CISA AA23-335A JOINT GOVERNMENT ADVISORY ERA (December 1, 2023). Five-government-agency joint advisory (US CISA + FBI + NSA + EPA + Israel National Cyber Directorate) operationally established canonical IRGC-CEC attribution and detailed tradecraft documentation. (4) US TREASURY SANCTIONS AND CUSTOM IOCONTROL MALWARE DEPLOYMENT (February 2024.
  • Mid-2024). February 2024 US Treasury sanctions against six IRGC-CEC officials + State Department Rewards for Justice $10M bounty. Mid-2024 Claroty Team82 disclosure of IOCONTROL custom Linux malware platform for IoT/OT environments, operationally maturing cluster capability from default-credential-exploitation to custom- malware operations across routers, PLCs, HMIs, IP cameras, firewalls, and fuel management systems. (5) CONTINUED OPERATIONS AND ECOSYSTEM PROLIFERATION (2024- 2026). Tradecraft proliferation across ~60 affiliated hacktivist groups per Tenable. January 2026 "Cyber4vengers" successor Telegram channel after prior channel removal. April 2026 CISA AA26-097A follow-up advisory with Shahid Kaveh Group naming confirming continued operational tempo.
Signature operational tradecraft includes
  • IRGC-CEC formal government attribution: Operationally distinct from most Iran-aligned clusters where attribution remains at broader "Iran-aligned" level, CyberAv3ngers is formally attributed by CISA to IRGC-CEC specifically.
  • Hacktivist-style public persona + Telegram channel: signature operational cover pattern, Persian-language Telegram channel claims responsibility for attacks with defacement imagery establishing "Israeli-made-equipment is CyberAv3ngers legal target" messaging theme.
  • Internet-exposed Unitronics PLC + factory-default- credential exploitation: signature initial-access tradecraft , operationally simple but operationally effective against target organizations with inadequate ICS/OT security hardening practices. CISA assessments found 70%+ non- compliance with existing safety requirements at US water utilities.
  • Israeli-made-equipment-specific targeting: signature operational pattern, cluster operations focused on Unitronics (Israel-based PLC manufacturer) equipment regardless of victim geography, operationally consistent with IRGC anti- Israeli operational mandates.
  • PLC ladder logic upload + HMI defacement: signature operational pattern of uploading malicious ladder logic to compromised PLCs and displaying defacement messages on integrated HMI displays, operationally distinct from typical cyber-espionage clusters that prioritize stealth.
  • IOCONTROL custom Linux malware for IoT/OT environments: signature post-Unitronics-era tooling maturation, custom- built Linux malware platform targeting routers, PLCs, HMIs, IP cameras, firewalls, fuel management systems from multiple vendors. MQTT-over-TLS C2 communication for legitimate-IoT- protocol traffic blending.
  • ICS / OT signature targeting: water and wastewater systems primary sector, fuel management systems secondary, agricultural irrigation tertiary, operationally distinct from competing Iran-aligned clusters with IT-focused targeting patterns.
  • Tradecraft proliferation to affiliated hacktivist ecosystem: ~60 affiliated hacktivist groups have adopted the internet-exposed-PLC-default-credential-exploitation tradecraft per Tenable analysis, operationally extending cluster impact beyond its own direct operations. The cluster fills the IRGC-CEC-attributed Iran-aligned APT cell with ICS/OT-specific targeting focus in this curated corpus, complementing the broader Iran-aligned cluster coverage (apt33_elfin, apt34_oilrig, apt35_charmingkitten, apt39_chafer, muddywater, imperial_kitten_tortoiseshell, agrius, hexane_lyceum). CyberAv3ngers is operationally distinct from these adjacent Iran-aligned clusters through (a) formal CISA-government-attribution to IRGC-CEC specifically; (b) signature ICS/OT industrial targeting (versus competing Iran-aligned cluster IT-focused targeting); (c) hacktivist-style public persona + Telegram channel claim-responsibility operational pattern; (d) signature Unitronics PLC + Israeli-made-equipment- specific targeting; (e) custom IOCONTROL Linux malware for IoT/OT environment targeting.

Aliases

19
cyberav3ngerscyberaveng3rscyber avengerscyber-avengerscyber_av3ngerscyber av3ngerscyber4vengersshahid kaveh groupshahid_kavehstorm-0784storm0784unc5691unc-5691hydro_kittenhydrokittenhydro kittencobalt_saplingcyberav3ngers_operatorsirgc_cec_cyberav3ngers

Notable Campaigns

11
2026CISA AA26-097A Follow-Up Advisory, Shahid Kaveh Group Naming (April 2026)
2024-2026Tradecraft Proliferation Across ~60 Affiliated Hacktivist Groups (2024-Present)
2024US Treasury Sanctions Against 6 IRGC-CEC Officials (February 2024)
2024IOCONTROL Custom Linux IoT/OT Malware Operational Deployment (Mid-2024)
2023-2024Multi-State US Water Facilities Campaign (November 22, 2023 - January 2024)
2023Israel Agricultural Irrigation Cyberattack (April 2023)
2023October 2023 Israel-Based PLC Targeting Surge (Post-October-7)
2023Municipal Water Authority of Aliquippa PA Compromise (November 25, 2023)
2023CISA AA23-335A Joint Government Advisory, IRGC-CEC Formal Attribution (December 1, 2023)
2022E-Post Israel Unitronics Compromise (February 2022)
2020CyberAv3ngers Operational Emergence (2020)

Attribution & Reporting

Attributed by
US CISAUS FBIUS NSAUS EPAIsrael National Cyber DirectorateUS Department of the TreasuryUS Department of State Rewards for JusticeMicrosoft Threat Intelligence CenterMandiantCrowdStrikeSecureWorks Counter Threat UnitSOPHOS X-OpsTenableClaroty Team82DragosCybel AngelRecorded Future Insikt GroupTrend Micro
Key reporting
reportUS CISA / FBI / NSA / EPA / Israel National Cyber Directorate: Joint Cybersecurity Advisory AA23-335A, IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities (December 1, 2023), canonical formal IRGC-CEC government attribution
reportUS CISA: Joint Cybersecurity Advisory AA26-097A, Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (April 2026), follow-up advisory with Shahid Kaveh Group naming
reportClaroty Team82: From Exploits to Forensics, Unraveling the Unitronics Attack; IOCONTROL Malware Analysis (mid-2024), canonical IOCONTROL malware disclosure
reportSOPHOS Counter Threat Unit (Secureworks): Iranian Cyber Av3ngers Compromise Unitronics Systems (December 2023), canonical SecureWorks operational tradecraft documentation
reportTenable: CyberAv3ngers FAQ on Iran-Linked Threat Group Targeting US Critical Infrastructure (April 2026), canonical Tenable phase-by-phase tradecraft progression analysis
reportMicrosoft Threat Intelligence: Storm-0784 Tracking and CyberAv3ngers Adjacent Activity
reportMandiant: UNC5691 Operational Tracking
reportCrowdStrike: Hydro Kitten Operational Profile, IRGC-aligned ICS targeting
reportDragos: The Rising Tide of Water Utility Cyber Threats, ICS-focused cyber-threat tracking
reportRecorded Future Insikt Group: Iran State-Aligned Cyber-Espionage and ICS Targeting Tracking
reportTrend Micro: IRGC-Affiliated Cluster Tracking
reportCybel Angel: Iranian Threat Actors Target US Critical Infrastructure Analysis
reportMITRE ATT&CK Group G1027, CyberAv3ngers
reportUS Department of State Rewards for Justice: IRGC-CEC CyberAv3ngers, Up to $10M Reward Notice (February 2024)
reportUS Department of the Treasury: Sanctions Against 6 IRGC-CEC Officials Tied to CyberAv3ngers (February 2024)

Operational

State sponsor

Islamic Republic of Iran state actor, formally attributed by the US Cybersecurity and Infrastructure Security Agency (CISA), FBI, NSA, Environmental Protection Agency (EPA), and Israel's National Cyber Directorate to the Iranian Government Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC). The IRGC is designated as a Foreign Terrorist Organization by the United States and Canada. The formal government cybersecurity attribution to a specific Iranian government agency operationally distinguishes CyberAv3ngers from many other Iran-aligned clusters where attribution remains at the broader "Iran-aligned" or "Iranian state- aligned" level. The first joint government advisory establishing the IRGC-CEC attribution was published December 1, 2023 (CISA Joint Advisory AA23-335A). A follow-up advisory (CISA AA26-097A) was published in April 2026 with additional tradecraft documentation and the canonical "Shahid Kaveh Group" naming for the IRGC-CEC unit. In February 2024 the US Department of the Treasury announced sanctions against six IRGC-CEC officials tied to CyberAv3ngers operations. The US State Department's Rewards for Justice programme has offered up to US$10 million for information on the group's identified operators. The cluster operationally uses the "CyberAv3ngers" hacktivist-style public persona, a Persian-language Telegram channel claiming responsibility for attacks accompanied by defacement images stating "You have been hacked, down with Israel. Every equipment 'made in Israel' is CyberAv3ngers legal target." SecureWorks Counter Threat Unit assesses that "Cyber Av3ngers is operated by an Iranian state-sponsored threat group in the same way that COBALT SAPLING operates the Moses Staff and Abraham's Ax personas", operationally consistent with the broader IRGC pattern of operating state- sponsored cyber operations under hacktivist-style cover personas. CISA documentation references "earliest CyberAv3ngers activity" dating to 2020 against Israel, operationally consistent with longer-running IRGC-CEC operations against Israel that were rebranded under the CyberAv3ngers persona. The November 2023 Aliquippa Pennsylvania water authority attack triggered the broader CISA/FBI/NSA/EPA/Israeli National Cyber Directorate joint advisory that operationally established the cluster's canonical multi-vendor government naming. The cluster is operationally distinct from the broader Iran-aligned clusters already curated in this corpus (apt33_elfin, apt34_oilrig, apt35_charmingkitten, apt39_chafer, muddywater, imperial_kitten_tortoiseshell, agrius, hexane_lyceum), operationally distinguished by (a) formal CISA-government-attribution to IRGC-CEC specifically (versus broader Iran-aligned attribution for other clusters)

(b) signature ICS / OT industrial targeting (water utilities, water and wastewater systems, fuel management systems, distinct from competing Iran-aligned cluster IT-focused targeting)

(c) signature hacktivist-style public persona + Telegram channel claim-responsibility operational pattern; (d) signature Unitronics PLC + Israeli-made-equipment- specific targeting.

(e) custom IOCONTROL Linux malware for IoT/OT environment targeting (Claroty Team82 disclosure mid- 2024).

Motivations
irgc_state_sponsored_disruptive_operations, israeli_made_equipment_targeting, hacktivism_style_public_messaging, critical_infrastructure_disruption, ics_ot_environment_compromise, water_and_wastewater_systems_targeting, fuel_management_systems_targeting, geopolitical_pressure_via_critical_infrastructure_attacks
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)50/60 · 83%
Analytics (MITRE CAR)28/60 · 46%
Runtime / container (Falco)9/60 · 15%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)13/60 · 21%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SHODAN OR ZOOMEYE INTERNET SCAN RECON

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin