Threadlinqs IntelligenceStart free

Threat actorIranTracked since 2026-03

Cyber Av3ngers

Also known as:CyberAv3ngersIRGC-CECShahid Kaveh GroupStorm-0784BauxiteUNC5691Hydro KittenSoldiers of SolomonAPT 33ATK35COBALT TRINITYElfin

As of 2026-09-27, Cyber Av3ngers is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning threat intel, ics scada, campaign. Also known as CyberAv3ngers, IRGC-CEC, Shahid Kaveh Group, Storm-0784. ATT&CK coverage spans 130 techniques across 32 tactics in 7 of 7 tracked threats. Most-observed techniques: T1071 (Application Layer Protocol), T1078 (Valid Accounts), T1565 (Data Manipulation).

Tracked threats
74 critical · 3 high
First seen
2026-03-06
Last seen
2026-08-18
ATT&CK techniques
130across 7 of 7 threats
Related CVEs
1Referenced by its activity
Attribution
IranNation or origin
Nation: Iran · 7 tracked threat(s) · Categories: THREAT_INTEL, ICS_SCADA, CAMPAIGN, MALWARE, APT

Activity timeline

Cyber Av3ngers appears in 7 tracked threats between and ; the busiest month was 2026-07 with 3 reports.

ATT&CK techniques observed

130 techniques observed across 7 of 7 tracked threats · Impact (11), Collection (10), Impact (ICS) (9), Execution (8), Persistence (8), Command and Control (7)
  • T1071 Application Layer Protocol — Command and Controlobserved in 4 of 7 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 4 of 7 tracked threats
  • T1565 Data Manipulation — Impactobserved in 4 of 7 tracked threats
  • T1571 Non-Standard Port — Command and Controlobserved in 4 of 7 tracked threats
  • T0869 Standard Application Layer Protocol — Command and Control (ICS)observed in 3 of 7 tracked threats
  • T1005 Data from Local System — Collectionobserved in 3 of 7 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 3 of 7 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 7 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 3 of 7 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 7 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 3 of 7 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 3 of 7 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 3 of 7 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 7 tracked threats
  • T1491 Defacement — Impactobserved in 3 of 7 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Cyber Av3ngers activity