logo

What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure

ID: 39069c3e-eb97-510f-b27e-b7dceeff99aa

STIX ID: report--39069c3e-eb97-510f-b27e-b7dceeff99aa

Feed Name: Tenable Blog

Threat Score
92/100

Date Published: 2026-04-09

Date Updated: 2026-05-01

Author: Research Special Operations

...
...

### Executive summary Tenable Research reports that the Iran-affiliated CyberAv3ngers group has matured into a state-directed ICS threat, deploying IOCONTROL malware and actively exploiting a critical, unpatchable authentication bypass (CVE-2021-22681) in Rockwell Logix controllers to disrupt U.S. water, energy, and government infrastructure; the advisory confirms operational impacts and provides urgent mitigations including disconnecting internet-exposed PLCs, enforcing segmentation, and applying defense-in-depth controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.