CyberAv3ngers

MITRE ATT&CK: G1027 View on attack.mitre.org

Aliases: Soldiers of Soloman, CyberAv3ngers

First seen
2020-01-01 00:00:00
Primary motivation
sabotage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
21 (1 malicious)
Last IoC activity
2026-09-12 13:17:30
Profile updated
2026-08-31 08:19:28

Targeted industries: energy-and-utilities healthcare-and-pharmaceutical manufacturing

Targeted regions: country_code:il

Context

The CyberAv3ngers are a suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated APT group. The CyberAv3ngers have been known to be active since at least 2020, with disputed and false claims of critical infrastructure compromises in Israel. In 2023, the CyberAv3ngers engaged in a global targeting and hacking of the Unitronics Programmable Logic Controller (PLC) with Human-Machine Interface (HMI). This PLC can be found in multiple sectors, including water and wastewater, energy, food and beverage manufacturing, and healthcare. The most notable feature of this attack was the defacement of the devices user interface.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to CyberAv3ngers (G1027). The 1 most recently updated:

TypeIndicatorUpdatedSources
IP address 175.110.121.41 2026-09-12 2

Reports & references

  • CISA — Aa23 335A (report)
  • MITRE ATT&CK — G1027 (report)

Attributed from

  • Unitronics Defacement Campaign (campaign)

External references