Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1071 ↗inferred | Application Layer Protocol | Command and Control | IOCONTROL OT/IoT implant uses MQTT for C2 (Claroty Team82) |
| T1491.002 ↗inferred | Defacement: External Defacement | Impact | defaced internet-exposed PLCs with anti-Israel messaging (CISA AA23-335A) |
| T1190 ↗inferred | Exploit Public-Facing Application | Initial Access | targeted internet-exposed Unitronics PLCs/HMIs (CISA AA23-335A) |
| T1078 ↗inferred | Valid Accounts | Initial Access | abused default credentials on exposed Unitronics devices (CISA AA23-335A) |
| T1587.001 ↗inferred | Develop Capabilities: Malware | Resource Development | developed the custom IOCONTROL OT/IoT malware (Claroty Team82) |
Regional co-occurrence is association, not prediction. These techniques appeared alongside CyberAv3ngers's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter CyberAv3ngers's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.