CyberAv3ngers is an IRGC-Cyber-Electronic-Command-affiliated group that, from late 2023, attacked internet-exposed Unitronics PLCs at water and wastewater utilities and other OT environments — including U.S. facilities using Israeli-made equipment — and in 2024 deployed the IOCONTROL malware against OT/IoT devices, blending hacktivist messaging with genuine ICS impact.
CyberAv3ngers was formally attributed by CISA, the FBI, NSA, and partners in a December 2023 joint advisory (AA23-335A) to actors affiliated with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC); the U.S. Treasury later sanctioned associated IRGC-CEC individuals. Attribution is medium-high confidence given the government sourcing; the group presents a hacktivist face but is assessed as a state-directed OT-attack actor. It has no MITRE Group ID, flagged here.
The group's defining 2023 activity was the mass compromise of Unitronics Vision-series programmable logic controllers (PLCs/HMIs) exposed to the internet with default credentials and default port 20256. After the outbreak of the Israel-Hamas war, CyberAv3ngers defaced these devices with anti-Israel messaging — 'You have been hacked, down with Israel' — explicitly because the equipment is Israeli-made, causing disruption at water/wastewater utilities and other facilities. In 2024, Claroty's Team82 and others documented the group's custom IOCONTROL malware, a Linux-based implant targeting OT/IoT and SCADA-adjacent devices (routers, PLCs, HMIs, firewalls) from multiple vendors.
MENA relevance is dual: Israel is the ideological and equipment target (Unitronics is an Israeli firm), and the campaign's political framing is anti-Israel, while the physical impact fell on utilities in the U.S. and elsewhere that deploy the Israeli-made gear — a novel supply-chain-of-ideology targeting model. The activity sits within the broader Iran-Israel conflict escalation.
CyberAv3ngers remained active through 2024 with the IOCONTROL disclosures and continued OT interest, and is assessed as active. It is included as a clean, government-sourced recent OT/ICS entry (medium-high confidence).
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.