logo

Iran-Linked CyberAv3ngers Sets Sights on Water Utilities and Industrial Controllers

ID: e1b124a7-9f4e-522e-b9e5-968ef2ebba70

STIX ID: report--e1b124a7-9f4e-522e-b9e5-968ef2ebba70

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-04-13

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

An Iran-backed actor known as CyberAv3ngers (aka Storm-0784/Bauxite/UNC5691) has transitioned from hacktivism into a capable state‑directed threat against water, energy, and government infrastructure. The group uses a modular Linux-based malware platform called IOCONTROL that blends into IoT traffic (MQTT over TLS, DoH), has compromised Unitronics and Rockwell Logix PLCs — including exploitation of CVE-2021-22681 — and has caused operational disruption and financial loss; US agencies issued advisory AA26-097A with mitigations and recommended IOC ingestion and network segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.