State-sponsored OT threat group
CyberAv3ngers
An IRGC-affiliated threat persona associated with disruptive targeting of exposed operational technology, most visibly the 2023 Unitronics PLC/HMI campaign.
- Primary focus
- Internet-exposed operational technology and critical infrastructure
- State alignment
- Iran
- Microsoft family
- Sandstorm
- CyberAv3ngers persona
- 2020
- Global Unitronics campaign
- 2023
- Last reviewed
- 2026-07-16
Designations
Aliases and related groups
The same activity is tracked under several vendor names. Each designation is listed separately below.
MITRE ATT&CK
CyberAv3ngers
G1027
MITRE's group record for the persona and its Unitronics defacement campaign.
SourcesMITRE ATT&CKNote: overlapping names are not proof that two vendors track exactly the same people, infrastructure or operations.
Key assessment
Key judgements
CyberAv3ngers achieved operational disruption through low-complexity access paths: exposed Unitronics controllers, default or absent credentials, replacement of ladder logic and defacement of HMI displays.
SourcesCISAMITRE ATT&CKThe persona has mixed verified intrusions with disputed or false claims of Israeli critical-infrastructure compromise, so public claims require independent technical corroboration.
SourcesMITRE ATT&CKCISAIOCONTROL expands the overlap activity from opportunistic PLC defacement to persistent Linux access across OT and IoT device families, but the malware itself contains no ICS-specific process logic.
SourcesClaroty Team82DragosTargeting
Regions, sectors and technology
Regions
- United StatesSourcesCISAMITRE ATT&CK
- IsraelSourcesMITRE ATT&CKClaroty Team82
- Europe and AustraliaSourcesCISADragos
Sectors
- Water and wastewaterSourcesCISAMITRE ATT&CK
- Energy and fuel distributionSourcesCISAClaroty Team82
- Food and beverage manufacturingSourcesCISAMITRE ATT&CK
- HealthcareSourcesCISAMITRE ATT&CK
- Industrial manufacturingSourcesDragos
Technology
- Unitronics Vision PLC/HMISourcesCISAMITRE ATT&CK
- Orpak and Gasboy fuel-management systemsSourcesClaroty Team82
- Linux-based OT and IoT devicesSourcesClaroty Team82Dragos
Campaign chronology
Timeline
- November 2023 - January 2024High confidence
CyberAv3ngers / government-attributed activity
Unitronics defacement campaign
IRGC-affiliated actors accessed internet-facing Unitronics PLC/HMI devices using default or absent passwords, replaced ladder logic and changed operator displays.
Operational consequence: At least 75 U.S. devices were affected, including at least 34 water and wastewater facilities; consequences included loss of view, availability and normal operation.
SourcesCISAMITRE ATT&CKU.S. Treasury - 2020 onwardHigh confidence
CyberAv3ngers public persona
Disputed Israeli infrastructure claims
The group has publicized claims of critical-infrastructure compromise in Israel, some of which government reporting describes as false or disputed.
Operational consequence: Information effects can exaggerate technical reach and complicate attribution and incident validation.
SourcesMITRE ATT&CKCISA - 2024; publicly detailed November - DecemberHigh confidence
BAUXITE / CyberAv3ngers overlap
IOCONTROL deployment
Custom Linux payloads established MQTT-based remote access across multiple OT and IoT device families.
Operational consequence: Persistent command execution and potential lateral movement from embedded devices; no ICS-specific process capability was identified in the malware.
SourcesClaroty Team82Dragos
Capabilities and malware
Capabilities and tooling
Access exposed PLC/HMI devices
Authenticate to publicly reachable Unitronics devices through default or absent credentials.
SourcesCISAMITRE ATT&CKReplace ladder logic and operator graphics
Erase original logic, download actor-controlled logic and replace the HMI display.
SourcesCISAMITRE ATT&CKMaintain Linux device access
Deploy IOCONTROL for remote command execution and persistence over encrypted MQTT communications.
SourcesClaroty Team82BAUXITE / CyberAv3ngers overlap
High confidenceIOCONTROL
A device-specific Linux backdoor using MQTT over TCP 8883 for command and control; public analysis found no ICS-specific logic.
SourcesClaroty Team82DragosTactics, techniques and procedures
Mapped ATT&CK techniques
Each mapping names the provider or activity scope that supports it. Overlap is not treated as proof that every designation describes an identical operation.
Enterprise ATT&CK
Enterprise access and manipulation
-
T1110Brute ForceActors attempted password access against exposed devices and services.
High confidenceSourcesCISA -
T1078.001Valid Accounts: Default AccountsDefault Unitronics password 1111 and absent authentication enabled access.
High confidenceSourcesCISA -
T1565.001Data Manipulation: Stored Data ManipulationThe actors replaced ladder logic and HMI content stored on affected controllers.
High confidenceSourcesCISA
ICS ATT&CK
ICS effects and access
-
T0883Internet Accessible DevicePublicly reachable Unitronics PLC/HMI devices and cellular equipment were targeted.
High confidenceSourcesMITRE ATT&CK -
T1694.001Insecure Credentials: Default CredentialsFactory-set credentials were used to access exposed controllers.
High confidenceSourcesMITRE ATT&CKCISA -
T0814Denial of ServiceController defacement and communication failure prevented normal device operation.
High confidenceSourcesMITRE ATT&CK -
T0826Loss of AvailabilityAffected organisations halted operations when PLC/HMI functions became unavailable.
High confidenceSourcesMITRE ATT&CK -
T0828Loss of Productivity and RevenueIndustrial disruption interfered with normal business operations.
High confidenceSourcesMITRE ATT&CK -
T0829Loss of ViewReplacement graphics prevented operators from viewing PLC information on the HMI.
High confidenceSourcesMITRE ATT&CK
Indicator handling
Historical indicators
Indicators associated with the 2024 IOCONTROL reporting are historical and may now be reassigned, sinkholed or benign. Use them only with source date, enrichment and behavioural context.
This profile intentionally prioritises sourced behaviour, access paths and operational context.
Source register
Sources
Publication and update dates preserve the point-in-time context used for this review.
- MITRE ATT&CKknowledge base
CyberAv3ngers, Group G1027
Published 25 March 2024 · Updated 10 April 2024
- CISAgovernment advisory
IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors
Published 1 December 2023 · Updated 18 December 2024
- U.S. Treasurygovernment attribution
Treasury Sanctions Actors Responsible for Malicious Cyber Activities on Critical Infrastructure
Published 2 February 2024
- Dragosthreat group profile
BAUXITE threat group profile
Published 3 September 2025
- Claroty Team82malware research
Inside a New OT/IoT Cyberweapon: IOCONTROL
Published 11 December 2024