Activity timeline
Cyber Av3ngers appears in 7 tracked threats between and ; the busiest month was 2026-07 with 3 reports.
ATT&CK techniques observed
- T1071 Application Layer Protocol — Command and Controlobserved in 4 of 7 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 4 of 7 tracked threats
- T1565 Data Manipulation — Impactobserved in 4 of 7 tracked threats
- T1571 Non-Standard Port — Command and Controlobserved in 4 of 7 tracked threats
- T0869 Standard Application Layer Protocol — Command and Control (ICS)observed in 3 of 7 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 7 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 3 of 7 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 7 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 3 of 7 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 7 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 3 of 7 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 3 of 7 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 3 of 7 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 7 tracked threats
- T1491 Defacement — Impactobserved in 3 of 7 tracked threats
Tracked threats
- Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch TimelinesHIGH
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguardsHIGH
- Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)CRITICAL
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting BahrainHIGH
- GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 CapabilitiesCRITICAL
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)CRITICAL
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)CRITICAL