The four features of this adversary's intrusions under the Diamond Model — adversary, capability, infrastructure, victim — assembled from tracked data; pivot from any vertex to the others.
Adversary3
Who is behind the activity — operator vs. customer.
CyberAv3ngersCyberAveng3rsCyberAvengers
Capability5
Tradecraft, techniques, and tooling the adversary employs.
5 ATT&CK techniquesInitial AccessCommand and ControlImpactResource Development
Infrastructure
Physical/logical infrastructure used to deliver capability (C2, domains, relays).
No infrastructure indicators correlated in Radar yet.
Operator ↔ CustomerOperator (intrusion crew) acting for a Customer (sponsoring interest) — attribution separates the two.
Honesty note
Attribution ≠ confirmation. CyberAv3ngers is linked here via TTP overlap and shared infrastructure — not confirmed by original-source reporting. Treat this as a working hypothesis, not a settled fact.
The actor's techniques grouped into kill-chain phases — a partial order across phases; techniques within a phase are co-occurring, not sequenced. Export opens in CTID's Attack Flow Builder.
5 techniques across 4 of 7 stages · 3 of 6 pre-objective stages show known tradecraft — each a chance to break the chain before Actions on Objectives.
1Reconnaissance
2Weaponization1
T1587.001
3Delivery2
T1190T1078
4Exploitation
5Installation
6Command & Control1
T1071
7Actions on Objectives1
T1491.002
Honesty note
Phase groupings reflect ATT&CK tactic classification, not a confirmed operational timeline for CyberAv3ngers — see the competing-hypotheses breakdown for how confident this attribution really is.
◆No financial or extortion motive — activity is purely disruptive/defacementIR reporting · C2
C
N
C
◆Operational tempo tracks geopolitical events, not opportunistic mass scanninganalyst · C3
C
I
C
◆Absence of publicly confirmed direct IRGC tasking ordersopen reporting · C3
I
C
C
Inconsistencies (lower wins)
2
3 · most inconsistent
0 ◀ lead
ConclusionMost consistent with an IRGC-enabled, deliberately deniable proxy (h3, zero inconsistencies): state-aligned targeting and tempo, but a loud hacktivist persona and the absence of public tasking orders preserve deniability. A pure state-run hypothesis (h1) carries two inconsistencies; the independent-hacktivist hypothesis (h2) is rejected on three. Assessed Moderate confidence — the lead is not fragile (two-inconsistency margin). Worked example of the ACH technique, not a formal RaqibCTI attribution.
Analysis of Competing Hypotheses (Heuer): the most diagnostic evidence disproves hypotheses. ◆ marks diagnostic rows; C = consistent, I = inconsistent, N = not applicable, · = not yet scored. The least-inconsistent hypothesis leads — it is not “proven”. Weigh each row by its source & credibility note (shown after the evidence): a high-credibility inconsistency disproves more than a doubtful one. The raw count never weighs this automatically — it stays your judgment — though when co-leads tie an advisory tiebreak may use credibility to suggest a lead (see the caveat above).
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.