Skip to actor profile
activeTLP:CLEARHigh confidence

State-aligned OT threat group

BAUXITE

A Dragos-designated, state-aligned OT threat group linked by substantial technical overlap to the IRGC-affiliated CyberAv3ngers persona.

Primary focus
Operational technology and industrial control systems
State alignment
Iran
Microsoft family
Sandstorm
BAUXITE activity cluster
2017
CyberAv3ngers persona
2020
Last reviewed
2026-07-16

Designations

Aliases and related groups

The same activity is tracked under several vendor names. Each designation is listed separately below.

PrimaryHigh confidence

Dragos

BAUXITE

The primary name for the activity cluster described in this profile.

SourcesDragos

Note: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.

Key assessment

Key judgements

High confidence

BAUXITE is an OT-focused activity cluster capable of reaching Stage 2 of the ICS Cyber Kill Chain. Public reporting describes PLC compromise, ladder-logic modification, internet-scale reconnaissance and custom Linux backdoor deployment against OT and IoT devices.

SourcesDragosDragos
High confidence

The public evidence supports a strong overlap with CyberAv3ngers, but vendor and government labels represent different analytic scopes. This profile therefore keeps BAUXITE, CyberAv3ngers, G1027 and IRGC-affiliated reporting visibly separated.

SourcesDragosMITRE ATT&CKCISA and partner agencies
High confidence

Observed operations favour exposed devices, default or absent credentials, publicly documented weaknesses and device-specific payloads. The resulting risk is disproportionate because modest access paths can produce loss of view, availability and operator control in physical processes.

SourcesCISA and partner agenciesMITRE ATT&CKDragos

Targeting

Regions, sectors and technology

Campaign chronology

Timeline

  1. November 2023 – January 2024High confidence

    CyberAv3ngers overlap activity

    Unitronics targeting waves

    IRGC-affiliated actors accessed internet-facing Unitronics PLC/HMI devices that used default or no passwords, replaced ladder logic and defaced operator displays. CISA reports at least 75 affected U.S. devices, including at least 34 in water and wastewater.

    Operational consequence: Loss of view, loss of availability, operational interruption and the potential for deeper cyber-physical effects.

    SourcesCISA and partner agenciesMITRE ATT&CKU.S. Department of the Treasury
  2. June – July 2024High confidence

    BAUXITE

    OT reconnaissance and research

    Dragos observed reconnaissance and research against OT/ICS entities and devices. No follow-on activity was observed publicly, but the collection was assessed as useful preparation for later disruptive operations.

    Operational consequence: Reduced preparation cost for later attempts to manipulate control and view or cause loss of availability.

    SourcesDragos
  3. 2024; publicly detailed November – DecemberHigh confidence

    BAUXITE / CyberAv3ngers overlap

    IOCONTROL deployment

    A custom Linux backdoor was compiled for multiple OT and IoT device families and communicated with command infrastructure over MQTT on TCP 8883 after resolving its domain through DNS over HTTPS. Dragos reported approximately 400 confirmed victims.

    Operational consequence: Persistent remote command execution, port scanning, self-deletion and potential lateral movement from embedded devices. Dragos notes that the malware itself contains no ICS-specific functionality.

    SourcesDragosClaroty Team82

Capabilities and malware

Capabilities and tooling

High confidenceCyberAv3ngers overlap activity

Compromise exposed PLCs and modify ladder logic

Public reporting documents authentication to exposed Unitronics devices, erasure of original ladder logic and download of actor-controlled logic.

SourcesCISA and partner agenciesMITRE ATT&CK
High confidenceBAUXITE

Exploit public knowledge and weak device security

BAUXITE tracks OEM and protocol advisories, uses publicly known exploits and benefits from default credentials and exposed management services.

SourcesDragosCISA and partner agencies
High confidenceBAUXITE / CyberAv3ngers overlap

Deploy tailored Linux backdoors

IOCONTROL is a modular embedded-Linux backdoor with MQTT command and control, command execution, port scanning and persistence functions.

SourcesDragosClaroty Team82
High confidenceBAUXITE

Conduct internet-scale OT research

The group researches exposed devices, OEM material and ICS protocol information to catalogue future opportunities.

SourcesDragosDragos

Embedded Linux backdoor

High confidence

IOCONTROL

A target-configurable backdoor for Linux-based OT and IoT devices. It uses encrypted MQTT communications, DNS over HTTPS for C2 resolution, daemon-based persistence and commands for execution, scanning and self-deletion.

Scope caveat: Dragos assesses that IOCONTROL has no ICS-specific functionality even though compromised devices can sit in or affect operational environments.

SourcesDragosClaroty Team82

Tactics, techniques and procedures

Mapped ATT&CK techniques

Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.

Enterprise ATT&CK

Enterprise access and manipulation

Download Navigator layer

ICS ATT&CK

ICS effects and access

Download Navigator layer

Indicator handling

Historical indicators

Historical, not current infrastructure.

These IOCONTROL indicators were published in December 2024 and are retained for historical hunting and retrospective review. CISA removed its original Unitronics indicators after they became outdated. Do not treat any value as current infrastructure without fresh validation.

  • IPV4historical
    159[.]100[.]6[.]69

    IOCONTROL command-and-control address at the time of Claroty's research.

    Reported 2024-12-11SourcesClaroty Team82
  • DOMAINhistorical
    uuokhhfsdlk[.]tylarion867mino[.]com

    Hard-coded IOCONTROL command-and-control hostname resolved through DNS over HTTPS.

    Reported 2024-12-11SourcesClaroty Team82
  • DOMAINhistorical
    ocferda[.]com

    Older domain reported as sharing the IOCONTROL command infrastructure address.

    Reported 2024-12-11SourcesClaroty Team82
  • SHA256historical
    1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498

    SHA-256 of the IOCONTROL sample analysed by Claroty Team82.

    Reported 2024-12-11SourcesClaroty Team82
  • PATHhistorical
    /usr/bin/iocontrol

    Initial IOCONTROL sample path.

    Reported 2024-12-11SourcesClaroty Team82
  • PATHhistorical
    /etc/rc3.d/S93InitSystemd.sh

    Service path used for IOCONTROL persistence in the analysed sample.

    Reported 2024-12-11SourcesClaroty Team82

Source register

Sources

Publication and update dates preserve the point-in-time context used for this review.

  1. DragosVendor threat profile

    BAUXITE threat group profile

    Published 9 March 2026

  2. DragosAnnual threat report

    2025 OT Cybersecurity Report: A Year in Review

    Published 25 February 2025

  3. MITRE ATT&CKATT&CK group profile

    CyberAv3ngers, Group G1027

    Published 25 March 2024 · Updated 10 April 2024

  4. CISA and partner agenciesJoint cybersecurity advisory

    IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors

    Published 1 December 2023 · Updated 18 December 2024

  5. Claroty Team82Malware research report

    Inside a New OT/IoT Cyberweapon: IOCONTROL

    Published 11 December 2024

  6. U.S. Department of the TreasuryGovernment attribution and sanctions notice

    Treasury Sanctions Actors Responsible for Malicious Cyber Activities on Critical Infrastructure

    Published 2 February 2024