Skip to actor profile
activeTLP:CLEARHigh confidence

State-sponsored OT threat group

CyberAv3ngers

An IRGC-affiliated threat persona associated with disruptive targeting of exposed operational technology, most visibly the 2023 Unitronics PLC/HMI campaign.

Primary focus
Internet-exposed operational technology and critical infrastructure
State alignment
Iran
Microsoft family
Sandstorm
CyberAv3ngers persona
2020
Global Unitronics campaign
2023
Last reviewed
2026-07-16

Designations

Aliases and related groups

The same activity is tracked under several vendor names. Each designation is listed separately below.

PrimaryHigh confidence

MITRE ATT&CK

CyberAv3ngers

G1027

MITRE's group record for the persona and its Unitronics defacement campaign.

SourcesMITRE ATT&CK

Note: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.

Key assessment

Key judgements

High confidence

CyberAv3ngers achieved operational disruption through low-complexity access paths: exposed Unitronics controllers, default or absent credentials, replacement of ladder logic and defacement of HMI displays.

SourcesCISAMITRE ATT&CK
High confidence

The persona has mixed verified intrusions with disputed or false claims of Israeli critical-infrastructure compromise, so public claims require independent technical corroboration.

SourcesMITRE ATT&CKCISA
High confidence

IOCONTROL expands the overlap activity from opportunistic PLC defacement to persistent Linux access across OT and IoT device families, but the malware itself contains no ICS-specific process logic.

SourcesClaroty Team82Dragos

Targeting

Regions, sectors and technology

Campaign chronology

Timeline

  1. November 2023 - January 2024High confidence

    CyberAv3ngers / government-attributed activity

    Unitronics defacement campaign

    IRGC-affiliated actors accessed internet-facing Unitronics PLC/HMI devices using default or absent passwords, replaced ladder logic and changed operator displays.

    Operational consequence: At least 75 U.S. devices were affected, including at least 34 water and wastewater facilities; consequences included loss of view, availability and normal operation.

    SourcesCISAMITRE ATT&CKU.S. Treasury
  2. 2020 onwardHigh confidence

    CyberAv3ngers public persona

    Disputed Israeli infrastructure claims

    The group has publicized claims of critical-infrastructure compromise in Israel, some of which government reporting describes as false or disputed.

    Operational consequence: Information effects can exaggerate technical reach and complicate attribution and incident validation.

    SourcesMITRE ATT&CKCISA
  3. 2024; publicly detailed November - DecemberHigh confidence

    BAUXITE / CyberAv3ngers overlap

    IOCONTROL deployment

    Custom Linux payloads established MQTT-based remote access across multiple OT and IoT device families.

    Operational consequence: Persistent command execution and potential lateral movement from embedded devices; no ICS-specific process capability was identified in the malware.

    SourcesClaroty Team82Dragos

Capabilities and malware

Capabilities and tooling

High confidenceCyberAv3ngers

Access exposed PLC/HMI devices

Authenticate to publicly reachable Unitronics devices through default or absent credentials.

SourcesCISAMITRE ATT&CK
High confidenceCyberAv3ngers

Replace ladder logic and operator graphics

Erase original logic, download actor-controlled logic and replace the HMI display.

SourcesCISAMITRE ATT&CK
High confidenceOverlap activity

Maintain Linux device access

Deploy IOCONTROL for remote command execution and persistence over encrypted MQTT communications.

SourcesClaroty Team82

BAUXITE / CyberAv3ngers overlap

High confidence

IOCONTROL

A device-specific Linux backdoor using MQTT over TCP 8883 for command and control; public analysis found no ICS-specific logic.

SourcesClaroty Team82Dragos

Tactics, techniques and procedures

Mapped ATT&CK techniques

Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.

Enterprise ATT&CK

Enterprise access and manipulation

Download Navigator layer
  • T1110Brute Force
    Credential AccessGovernment-attributed Unitronics activity

    Actors attempted password access against exposed devices and services.

    High confidenceSourcesCISA
  • T1078.001Valid Accounts: Default Accounts
    Defense Evasion / Persistence / Initial AccessGovernment-attributed Unitronics activity

    Default Unitronics password 1111 and absent authentication enabled access.

    High confidenceSourcesCISA
  • T1565.001Data Manipulation: Stored Data Manipulation
    ImpactGovernment-attributed Unitronics activity

    The actors replaced ladder logic and HMI content stored on affected controllers.

    High confidenceSourcesCISA

ICS ATT&CK

ICS effects and access

Download Navigator layer

Indicator handling

Historical indicators

Historical, not current infrastructure.

Indicators associated with the 2024 IOCONTROL reporting are historical and may now be reassigned, sinkholed or benign. Use them only with source date, enrichment and behavioural context.

No point-in-time indicators published.

This profile intentionally prioritises sourced behaviour, access paths and operational context.

Source register

Sources

Publication and update dates preserve the point-in-time context used for this review.

  1. MITRE ATT&CKknowledge base

    CyberAv3ngers, Group G1027

    Published 25 March 2024 · Updated 10 April 2024

  2. CISAgovernment advisory

    IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors

    Published 1 December 2023 · Updated 18 December 2024

  3. U.S. Treasurygovernment attribution

    Treasury Sanctions Actors Responsible for Malicious Cyber Activities on Critical Infrastructure

    Published 2 February 2024

  4. Dragosthreat group profile

    BAUXITE threat group profile

    Published 3 September 2025

  5. Claroty Team82malware research

    Inside a New OT/IoT Cyberweapon: IOCONTROL

    Published 11 December 2024