# Cyber Av3ngers

> As of 2026-09-27, Cyber Av3ngers is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning threat intel, ics scada, campaign. Also known as CyberAv3ngers, IRGC-CEC, Shahid Kaveh Group, Storm-0784. ATT&CK coverage spans 130 techniques across 32 tactics in 7 of 7 tracked threats. Most-observed techniques: T1071 (Application Layer Protocol), T1078 (Valid Accounts), T1565 (Data Manipulation).

- **Nation:** Iran
- **Tracked threats:** 7
- **Categories:** THREAT_INTEL, ICS_SCADA, CAMPAIGN, MALWARE, APT
- **Also known as:** CyberAv3ngers, IRGC-CEC, Shahid Kaveh Group, Storm-0784, Bauxite, UNC5691, Hydro Kitten, Soldiers of Solomon, APT 33, ATK35, COBALT TRINITY, Elfin
- **As of:** 2026-09-27

## ATT&CK techniques observed

130 techniques observed across 7 of 7 tracked threats. Tactics: Impact (11), Collection (10), Impact (ICS) (9), Execution (8), Persistence (8), Command and Control (7).

- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 4 of 7 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 4 of 7 tracked threats
- [T1565](https://intel.threadlinqs.com/technique/T1565) Data Manipulation — Impact — observed in 4 of 7 tracked threats
- [T1571](https://intel.threadlinqs.com/technique/T1571) Non-Standard Port — Command and Control — observed in 4 of 7 tracked threats
- [T0869](https://attack.mitre.org/techniques/T0869/) Standard Application Layer Protocol — Command and Control (ICS) — observed in 3 of 7 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 7 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 3 of 7 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 7 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 3 of 7 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 7 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 3 of 7 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 7 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 3 of 7 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 3 of 7 tracked threats
- [T1491](https://intel.threadlinqs.com/technique/T1491) Defacement — Impact — observed in 3 of 7 tracked threats

## Tracked threats

- [Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines](https://intel.threadlinqs.com/threat/TL-2026-2058) — HIGH
- [Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards](https://intel.threadlinqs.com/threat/TL-2026-1882) — HIGH
- [Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)](https://intel.threadlinqs.com/threat/TL-2026-1697) — CRITICAL
- [ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain](https://intel.threadlinqs.com/threat/TL-2026-1659) — HIGH
- [GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 Capabilities](https://intel.threadlinqs.com/threat/TL-2026-1158) — CRITICAL
- [Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)](https://intel.threadlinqs.com/threat/TL-2026-0335) — CRITICAL
- [Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)](https://intel.threadlinqs.com/threat/TL-2026-0183) — CRITICAL

## Related CVEs

1 CVE referenced by tracked Cyber Av3ngers activity.

- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Cyber%20Av3ngers
