What is CyberAv3ngers?
CyberAv3ngers is a hacker persona that presents itself as an independent hacktivist group but, according to the US government, is run by the Cyber-Electronic Command of Iran’s Islamic Revolutionary Guard Corps (IRGC-CEC) and primarily attacks industrial control systems at water and energy utilities. The group became known worldwide in late 2023, when it took over dozens of internet-connected PLCs made by the Israeli manufacturer Unitronics, including one at a drinking water authority in Aliquippa, Pennsylvania. CyberAv3ngers typifies a wider trend: hacktivists, with or without state backing, breaking into poorly secured OT with very simple means.
🧠 Who is behind CyberAv3ngers?
The CyberAv3ngers name first appeared around 2020, but the group only came to prominence after the Israel–Hamas war broke out in October 2023. Officially it poses as an activist collective; in reality, according to CISA, the FBI and the US Treasury, it is a front for the IRGC-CEC. Security vendors track it as Storm-0784 (Microsoft), Bauxite (Dragos) and UNC5691 (Mandiant), and MITRE ATT&CK lists it as G1027.
That state link has had legal consequences:
- Sanctions (2 February 2024) — the US Office of Foreign Assets Control designated six IRGC-CEC officials, including its commander Hamid Reza Lashgarian, over the attacks on Unitronics PLCs
- Reward (August 2024) — the State Department’s Rewards for Justice programme offered up to USD 10 million for information on the same six individuals
- New reward (September 2026) — another offer of up to USD 10 million, this time for Amir Yaryab, who according to the US leads the IRGC-CEC’s cyber operations, including those of CyberAv3ngers
This makes it a textbook example of a state actor disguised as a hacktivist: the persona provides political cover and makes denial easier.
🔧 How did the Unitronics PLC attacks work?
From 22 November 2023, CyberAv3ngers scanned the internet for Unitronics Vision series PLCs with an integrated HMI. These compact controllers are common in pumping stations and small plants. The method was strikingly simple:
- Find — the attackers looked for devices reachable on TCP port 20256, the default port of the Unitronics PCOM protocol
-
Log in — many PLCs still had the factory password
1111, or no password at all - Deface — the screen displayed “You have been hacked, down with Israel. Every equipment ‘made in Israel’ is Cyberav3ngers legal target”
- Disable — in some cases the project was overwritten or the communication port changed, locking the owner out of the PLC
In Aliquippa, the target on 25 November 2023 was a booster station that maintains water pressure for two townships. An alarm alerted the operators, who took the system offline and ran it manually; the drinking water supply was never at risk. According to CISA advisory AA23-335A, at least 75 devices were compromised between November 2023 and January 2024, at least 34 of them in the US water and wastewater sector. Europe was hit too: in Erris, County Mayo, Ireland, around 180 households lost their water supply on 30 November and 1 December 2023 after the Unitronics PLC of a small community water scheme was taken over.
🗓️ Which attacks are attributed to CyberAv3ngers?
| Period | Event |
|---|---|
| October 2023 | Claims to have hacked Israel’s Dorad power station; the “evidence” turned out to be recycled material from an earlier leak |
| October 2023 – January 2024 | Orpak and Gasboy fuel management systems in Israel and the US actually compromised, later linked to IOCONTROL |
| November 2023 – January 2024 | Wave of attacks on Unitronics Vision PLCs: at least 75 devices, including Aliquippa and Erris |
| December 2023 | CISA and partners publish advisory AA23-335A |
| December 2024 | Claroty Team82 describes IOCONTROL, malware for Linux-based OT and IoT devices |
| April 2026 | Advisory AA26-097A: Iranian-affiliated actors tamper with Rockwell PLCs; the July 2026 update adds Schneider Electric and Siemens |
| July 2026 | More than thirty water systems in Minnesota hit (26–27 July); CyberAv3ngers claims the attack jointly with “APT Iran”, US agencies suspect Iran, but there is no formal attribution |
IOCONTROL marked a step up. The malware runs on embedded Linux systems such as routers, IP cameras, firewalls, PLCs and HMIs from vendors including D-Link, Hikvision, Phoenix Contact, Teltonika and Unitronics. It talks to its command server over MQTT, persists through a boot script, and can execute commands and scan the network. Advisory AA26-097A from 2026 shows a further shift: the attackers used the manufacturers’ own engineering software to steal and modify project files, change ladder logic and disable alarms, reaching the controllers over ports such as 44818, 2222, 102 and 502.
⚖️ How reliable are hacktivist claims?
Exaggeration is part of how a hacktivist persona operates. In 2023 CyberAv3ngers claimed to have taken down major Israeli power and water facilities, while researchers showed that the images it posted were old or fabricated. At the same time, other attacks, such as those on Orpak fuel systems and Unitronics PLCs, were very real. For defenders, this means every claim deserves a serious check but no panic: look at your own logs and assets rather than at Telegram.
🌍 Which other hacktivists target OT?
CyberAv3ngers is not alone. Pro-Russian groups have followed a similar pattern since 2022. On 9 December 2025, CISA, the FBI, the NSA and partners including Europol and Germany’s BSI published advisory AA25-343A on Cyber Army of Russia Reborn (CARR), NoName057(16), Z-Pentest (active since September 2024) and Sector16 (since January 2025). These groups look for HMIs exposed to the internet through unsecured VNC on port 5900, guess or bypass the password, change settings, switch off alarms and film everything for social media.
| Incident | Date | Actor | Consequence |
|---|---|---|---|
| Muleshoe, Texas | January 2024 | CARR, linked by Mandiant to Sandworm | Water tank overflowed for 30–45 minutes |
| Bremanger, Norway | April 2025 | Pro-Russian actor according to Norwegian authorities | Dam valve left open for about four hours |
| Forescout honeypot | September 2025 | TwoNet | Decoy water treatment plant taken over via default password, settings changed and alarms disabled |
In the Netherlands, visible hacktivism has so far been limited mainly to DDoS attacks by NoName057(16) on government websites, including around the NATO summit in June 2025. The Forescout honeypot shows, however, how quickly these groups find and take over an internet-exposed HMI, whichever country it sits in.
⚠️ Why do such simple attacks still work?
The attacks by CyberAv3ngers and the pro-Russian groups require no zero-days or advanced malware. They succeed because of three structural weaknesses:
- Internet exposure — PLCs, HMIs and VNC servers are directly reachable from the internet, often because an integrator once needed remote access
-
Default credentials —
1111, no password at all, or shared accounts without MFA - Small organisations — small water utilities and municipal plants rarely have their own OT security team, yet they operate critical infrastructure
The gap with an advanced attack, such as the one on the Polish energy system in late 2025, is large in terms of skill but small in terms of impact for anyone who has not got the basics right.
🔐 How do you protect your installations against hacktivists?
| Measure | What you actually do |
|---|---|
| Off the internet | Check your public IP addresses for open ports such as 20256, 5900, 502, 102 and 44818, and close them |
| Remote access | Only through a VPN or managed gateway with MFA, never through port forwarding |
| Passwords | Change every factory password; for Unitronics, use VisiLogic 9.9.00 or later and current firmware |
| Segmentation | Separate OT from IT and the internet with network segmentation and default-deny firewalls |
| Inventory | Keep an up-to-date asset inventory, including 4G routers and modems |
| Detect changes | Regularly compare PLC projects with a known-good backup and keep any key switch in RUN |
| Vulnerabilities | Follow the KEV catalogue; the Unitronics flaw CVE-2023-6448 is on it |
| Manual operation | Rehearse running plants by hand, as Aliquippa and Erris had to |
For organisations within the scope of the Dutch Cybersecurity Act, these are not optional tips: the duty of care requires appropriate measures, and a successful takeover of a PLC can quickly become a reportable incident.
❓ Frequently asked questions
Is CyberAv3ngers a real hacktivist group?
CyberAv3ngers presents itself as a hacktivist group, but the US government regards it as a front for the Cyber-Electronic Command of Iran’s Islamic Revolutionary Guard Corps. That is why sanctions and rewards targeting IRGC officials have been issued. The activist branding mainly serves to spread propaganda and mask state involvement.
What password did the attackers use in Aliquippa?
In the CyberAv3ngers attack on Aliquippa in November 2023, a Unitronics PLC was connected to the internet
with the default password 1111. The attackers therefore did not need to exploit any
vulnerability. Changing factory passwords and shielding the PLC from the internet would have prevented the
attack.
What is IOCONTROL?
IOCONTROL is malware that Claroty Team82 linked to CyberAv3ngers in December 2024. It runs on Linux-based devices such as routers, PLCs, HMIs and firewalls and is controlled remotely over MQTT. It shows that CyberAv3ngers can do more than simply try default passwords.
Are European water utilities targeted by CyberAv3ngers?
Yes, at least once: in late 2023 CyberAv3ngers took over the Unitronics PLC of a small water scheme in County Mayo, Ireland, leaving around 180 households without water for two days. No CyberAv3ngers attack on a Dutch water company is publicly known. Because the group scans the internet worldwide, any exposed controller in Europe is a potential target.
What is the difference between hacktivists and an APT?
Hacktivists such as CyberAv3ngers or NoName057(16) act opportunistically, choose easy targets and seek publicity. An APT works in a targeted, stealthy and long-term way, as Sandworm did in its attacks on the Ukrainian power grid. The distinction is blurring because states use hacktivist personas as cover.
How can you check whether your PLC is exposed to the internet?
You can check by having your own public IP addresses scanned for industrial ports, or by looking them up in search engines such as Shodan and Censys. Do not forget 4G routers and installations managed by suppliers. Any device that can be found this way should be placed behind a VPN or firewall.
📌 In summary
CyberAv3ngers is an IRGC-linked hacker persona that has been taking over internet-connected PLCs at water utilities since 2023, often simply by using the factory password. Together with pro-Russian groups such as CARR and Z-Pentest, it proves that low technical skill is enough as long as OT is online: take controllers off the internet, change default passwords and rehearse manual operation.
