FlagThis
← Threat Actors
/
Iran
/
CyberAv3ngers
DOSSIER // CYBERAV3NGERS
CyberAv3ngers
ACTIVE CAMPAIGN TRACKED
▲ High Threat
Iran
Primary Aliases:
Hydro Kitten
Bauxite
G1027
Shahid Kaveh Group
🔍 Adversary Rosetta Stone (6) ▾
📋 Copy All
Sponsor / State Affiliation
Iran (suspected IRGC-linked)
Primary Motivation
Political sabotage and retaliation against Western and Israeli interests
Confidence Rating
85% (Grounded)
US Water Infrastructure Exploitation, Critical Infrastructure Probing
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
🎯 Target Sectors & Focus
Water and Wastewater Systems
Industrial Control Systems (ICS/SCADA)
Critical Infrastructure
IoT/IIoT Devices
Energy Sector
🛡️ MITRE ATT&CK® Attack Lifecycle
(5 TTPs)
📥 Download Navigator JSON
All Stages
5
Credential Access & Discovery
1
Command & Control
1
Operational Techniques
3
Credential Access & Discovery
1
T1003
Exploitation of default credentials
↗
Command & Control
1
T1071
Operational technology (OT) disruption
↗
Operational Techniques
3
T1000
Targeting of Unitronics Programmable Logic Controllers (PLCs)
↗
T1000
Website defacement
↗
T1000
Denial of Service (DoS)
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
CyberAv3ngers Target Unitronics, Federal Signal, and Genmark Siren Controllers in Psychological Warfare Campaign
Attacks and Vulnerabilities
2026-06-27
[DEEP DIVE]
Iranian-Linked Cyber Av3ngers Campaign Targeting Unitronics PLCs
Attacks and Vulnerabilities
2026-08-16
[DEEP DIVE]
Coordinated Attack on Minnesota Water Infrastructure Targeting Rockwell Automation and Schneider Electric PLCs
Attacks and Vulnerabilities
2026-07-29
Adversary Rosetta Stone // CyberAv3ngers
×
🦅 CrowdStrike Monikers
Hydro Kitten
📋
🛡️ Other Industry Tracking Codes
Bauxite
📋
G1027
📋
Shahid Kaveh Group
📋
Soldiers of Solomon
📋
Storm-. 0784
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD