State-aligned OT threat group
BAUXITE
A Dragos-designated, state-aligned OT threat group linked by substantial technical overlap to the IRGC-affiliated CyberAv3ngers persona.
- Primary focus
- Operational technology and industrial control systems
- State alignment
- Iran
- Microsoft family
- Sandstorm
- BAUXITE activity cluster
- 2017
- CyberAv3ngers persona
- 2020
- Last reviewed
- 2026-07-16
Designations
Aliases and related groups
The same activity is tracked under several vendor names. Each designation is listed separately below.
Dragos
BAUXITE
The primary name for the activity cluster described in this profile.
SourcesDragosNote: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.
Key assessment
Key judgements
BAUXITE is an OT-focused activity cluster capable of reaching Stage 2 of the ICS Cyber Kill Chain. Public reporting describes PLC compromise, ladder-logic modification, internet-scale reconnaissance and custom Linux backdoor deployment against OT and IoT devices.
SourcesDragosDragosThe public evidence supports a strong overlap with CyberAv3ngers, but vendor and government labels represent different analytic scopes. This profile therefore keeps BAUXITE, CyberAv3ngers, G1027 and IRGC-affiliated reporting visibly separated.
SourcesDragosMITRE ATT&CKCISA and partner agenciesObserved operations favour exposed devices, default or absent credentials, publicly documented weaknesses and device-specific payloads. The resulting risk is disproportionate because modest access paths can produce loss of view, availability and operator control in physical processes.
SourcesCISA and partner agenciesMITRE ATT&CKDragosTargeting
Regions, sectors and technology
Regions
- United StatesSourcesDragosCISA and partner agencies
- AustraliaSourcesDragos
- United Kingdom and EuropeSourcesDragosCISA and partner agencies
- Israel and the Middle EastSourcesDragosCISA and partner agencies
Sectors
- Water and wastewaterSourcesCISA and partner agenciesMITRE ATT&CK
- Energy and fuel distributionSourcesCISA and partner agenciesClaroty Team82
- Food and beverage manufacturingSourcesCISA and partner agenciesMITRE ATT&CK
- HealthcareSourcesCISA and partner agenciesMITRE ATT&CK
- Industrial manufacturingSourcesDragosDragos
Technology
- Unitronics Vision PLC/HMISourcesCISA and partner agenciesMITRE ATT&CK
- Orpak and Gasboy fuel-management systemsSourcesClaroty Team82Dragos
- Linux-based OT and IoT devicesSourcesClaroty Team82Dragos
- Firewalls, routers, HMIs and embedded controllersSourcesClaroty Team82Dragos
Campaign chronology
Timeline
- November 2023 – January 2024High confidence
CyberAv3ngers overlap activity
Unitronics targeting waves
IRGC-affiliated actors accessed internet-facing Unitronics PLC/HMI devices that used default or no passwords, replaced ladder logic and defaced operator displays. CISA reports at least 75 affected U.S. devices, including at least 34 in water and wastewater.
Operational consequence: Loss of view, loss of availability, operational interruption and the potential for deeper cyber-physical effects.
SourcesCISA and partner agenciesMITRE ATT&CKU.S. Department of the Treasury - June – July 2024High confidence
BAUXITE
OT reconnaissance and research
Dragos observed reconnaissance and research against OT/ICS entities and devices. No follow-on activity was observed publicly, but the collection was assessed as useful preparation for later disruptive operations.
Operational consequence: Reduced preparation cost for later attempts to manipulate control and view or cause loss of availability.
SourcesDragos - 2024; publicly detailed November – DecemberHigh confidence
BAUXITE / CyberAv3ngers overlap
IOCONTROL deployment
A custom Linux backdoor was compiled for multiple OT and IoT device families and communicated with command infrastructure over MQTT on TCP 8883 after resolving its domain through DNS over HTTPS. Dragos reported approximately 400 confirmed victims.
Operational consequence: Persistent remote command execution, port scanning, self-deletion and potential lateral movement from embedded devices. Dragos notes that the malware itself contains no ICS-specific functionality.
SourcesDragosClaroty Team82
Capabilities and malware
Capabilities and tooling
Compromise exposed PLCs and modify ladder logic
Public reporting documents authentication to exposed Unitronics devices, erasure of original ladder logic and download of actor-controlled logic.
SourcesCISA and partner agenciesMITRE ATT&CKExploit public knowledge and weak device security
BAUXITE tracks OEM and protocol advisories, uses publicly known exploits and benefits from default credentials and exposed management services.
SourcesDragosCISA and partner agenciesDeploy tailored Linux backdoors
IOCONTROL is a modular embedded-Linux backdoor with MQTT command and control, command execution, port scanning and persistence functions.
SourcesDragosClaroty Team82Conduct internet-scale OT research
The group researches exposed devices, OEM material and ICS protocol information to catalogue future opportunities.
SourcesDragosDragosEmbedded Linux backdoor
High confidenceIOCONTROL
A target-configurable backdoor for Linux-based OT and IoT devices. It uses encrypted MQTT communications, DNS over HTTPS for C2 resolution, daemon-based persistence and commands for execution, scanning and self-deletion.
Scope caveat: Dragos assesses that IOCONTROL has no ICS-specific functionality even though compromised devices can sit in or affect operational environments.
SourcesDragosClaroty Team82Tactics, techniques and procedures
Mapped ATT&CK techniques
Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.
Enterprise ATT&CK
Enterprise access and manipulation
-
T1110Brute ForceCISA maps attempts against exposed Unitronics devices and their authentication paths to brute force activity.
High confidenceSourcesCISA and partner agencies -
T1078.001Valid Accounts: Default AccountsActors authenticated to internet-connected PLC/HMI devices that retained default credentials or had no password configured.
High confidenceSourcesCISA and partner agencies -
T1565.001Data Manipulation: Stored Data ManipulationThe actors erased original ladder-logic files and downloaded replacement logic intended to disrupt operation and frustrate recovery.
High confidenceSourcesCISA and partner agencies
ICS ATT&CK
ICS effects and access
-
T0883Internet Accessible DeviceThe Unitronics campaign reached PLC/HMI and supporting network devices directly exposed to the public internet.
High confidenceSourcesMITRE ATT&CKCISA and partner agencies -
T1694.001Insecure Credentials: Default CredentialsAffected devices used the Unitronics default password or no password, allowing remote authentication.
High confidenceSourcesMITRE ATT&CKCISA and partner agencies -
T0814Denial of ServiceController defacement and logic changes prevented normal operation and contributed to communications failures.
High confidenceSourcesMITRE ATT&CK -
T0826Loss of AvailabilityCompromised PLC/HMI devices became unavailable for normal business and operational use.
High confidenceSourcesMITRE ATT&CK -
T0828Loss of Productivity and RevenueVictims halted or constrained industrial activity while affected controllers were unavailable.
High confidenceSourcesMITRE ATT&CK -
T0829Loss of ViewReplacement HMI graphics prevented operators from viewing legitimate controller information.
High confidenceSourcesMITRE ATT&CKCISA and partner agencies
Indicator handling
Historical indicators
These IOCONTROL indicators were published in December 2024 and are retained for historical hunting and retrospective review. CISA removed its original Unitronics indicators after they became outdated. Do not treat any value as current infrastructure without fresh validation.
-
IPV4historical
159[.]100[.]6[.]69IOCONTROL command-and-control address at the time of Claroty's research.
Reported 2024-12-11SourcesClaroty Team82 -
DOMAINhistorical
uuokhhfsdlk[.]tylarion867mino[.]comHard-coded IOCONTROL command-and-control hostname resolved through DNS over HTTPS.
Reported 2024-12-11SourcesClaroty Team82 -
DOMAINhistorical
ocferda[.]comOlder domain reported as sharing the IOCONTROL command infrastructure address.
Reported 2024-12-11SourcesClaroty Team82 -
SHA256historical
1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498SHA-256 of the IOCONTROL sample analysed by Claroty Team82.
Reported 2024-12-11SourcesClaroty Team82 -
PATHhistorical
/usr/bin/iocontrolInitial IOCONTROL sample path.
Reported 2024-12-11SourcesClaroty Team82 -
PATHhistorical
/etc/rc3.d/S93InitSystemd.shService path used for IOCONTROL persistence in the analysed sample.
Reported 2024-12-11SourcesClaroty Team82
Source register
Sources
Publication and update dates preserve the point-in-time context used for this review.
- DragosVendor threat profile
BAUXITE threat group profile
Published 9 March 2026
- DragosAnnual threat report
2025 OT Cybersecurity Report: A Year in Review
Published 25 February 2025
- MITRE ATT&CKATT&CK group profile
CyberAv3ngers, Group G1027
Published 25 March 2024 · Updated 10 April 2024
- CISA and partner agenciesJoint cybersecurity advisory
IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors
Published 1 December 2023 · Updated 18 December 2024
- Claroty Team82Malware research report
Inside a New OT/IoT Cyberweapon: IOCONTROL
Published 11 December 2024
- U.S. Department of the TreasuryGovernment attribution and sanctions notice
Treasury Sanctions Actors Responsible for Malicious Cyber Activities on Critical Infrastructure
Published 2 February 2024