Threat Actor ๐ฎ๐ท Iran
Cyber Av3ngers
Also known as: CyberAv3ngers ยท Shahid Kaveh Group
Cyber Av3ngers is an Iranian IRGC Cyber-Electronic Command-affiliated threat actor that targets internet-exposed operational technology and industrial control systems. Public reporting documents disruptive targeting of Israeli-made Unitronics PLCs and HMIs, broader critical-infrastructure targeting, and use of the IOCONTROL malware against IoT and OT devices.
Indicators of Compromise 2
MITRE ATT&CK TTPs 3
Source Articles
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack impacted over 30 Minnesota community water systems on July 26โ27, 2026, disrupting operational technology including automated controls and communications infrastructure. Multiple plants reported outages or degraded operations, with Braham's water treatment facility going offline and Maple Plain declaring a local state of emergency. The attack exhibited common tactics across targets, such as access methods and timing, suggesting a coordinated campaign. While no specific vulnerability or malware was confirmed, the activity aligns with known tradecraft of Iranian-affiliated threat group CyberAv3ngers, which has previously targeted industrial control systems using programmable logic controllers and human-machine interfaces.
hacker-news ยท1mo ago
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft has analyzed a destructive Windows backdoor named GigaWiper, which combines disk-wiping, fake ransomware, and spyware capabilities. The malware, written in Go, allows operators to choose from multiple destructive payloads, including full disk wiping, overwriting the Windows drive, and fake encryption with no decryption key. It also includes surveillance features such as screen recording, VNC streaming, and system reconnaissance. The same malware was independently identified as BLUERABBIT by Binary Defense and is linked to an Iran-nexus group targeting Israeli organizations, with ties to prior threats like Crucio and FlockWiper.
hacker-news ยท1mo ago