FlagThis
← Threat Actors
/
Iran
/
Cyber Av3ngers
DOSSIER // CYBER-AV3NGERS
Cyber Av3ngers
ACTIVE CAMPAIGN TRACKED
▲ High Threat
Iran
Primary Aliases:
UNC5691
APT Iran
CL-STA-1128
Cyber Avengers
🔍 Adversary Rosetta Stone (11) ▾
📋 Copy All
Sponsor / State Affiliation
Iran (likely IRGC-linked)
Primary Motivation
Political disruption and retaliation
Confidence Rating
90% (Grounded)
Unitronics PLC Targeting Campaign, Storm-0784 OT Disruption Operations
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
🎯 Target Sectors & Focus
Water and Wastewater Systems
Critical Infrastructure
Industrial Control Systems (ICS)
Operational Technology (OT)
Utilities
Governmental Entities (Israel and US-based)
🛡️ MITRE ATT&CK® Attack Lifecycle
(5 TTPs)
📥 Download Navigator JSON
All Stages
5
Credential Access & Discovery
2
Operational Techniques
3
Credential Access & Discovery
2
T1003
Exploitation of default credentials
↗
T1003
Reconnaissance via Shodan/Censys
↗
Operational Techniques
3
T1000
Unauthorized access to Programmable Logic Controllers (PLCs)
↗
T1000
Targeted password guessing
↗
T1000
OT-specific protocol manipulation
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
Iranian-Linked Cyber Av3ngers Campaign Targeting Unitronics PLCs
Attacks and Vulnerabilities
2026-08-16
Adversary Rosetta Stone // Cyber Av3ngers
×
🔍 Mandiant / Google Threat Intel
UNC5691
📋
🛡️ Other Industry Tracking Codes
APT Iran
📋
CL-STA-1128
📋
Cyber Avengers
📋
CyberAv3ngers
📋
CyberAv3ngers_supp
📋
CyberAveng3rs
📋
Mr. Soul
📋
Shahid Kaveh Group
📋
Sons of Solomon
📋
Storm-0784
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD