Iran-Linked CyberAv3ngers Sets Sights on Water Utilities and Industrial Controllers
ID: e1b124a7-9f4e-522e-b9e5-968ef2ebba70
STIX ID: report--e1b124a7-9f4e-522e-b9e5-968ef2ebba70
Feed Name: cybersecurityNews.com
An Iran-backed actor known as CyberAv3ngers (aka Storm-0784/Bauxite/UNC5691) has transitioned from hacktivism into a capable state‑directed threat against water, energy, and government infrastructure. The group uses a modular Linux-based malware platform called IOCONTROL that blends into IoT traffic (MQTT over TLS, DoH), has compromised Unitronics and Rockwell Logix PLCs — including exploitation of CVE-2021-22681 — and has caused operational disruption and financial loss; US agencies issued advisory AA26-097A with mitigations and recommended IOC ingestion and network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
