CyberAv3ngers
MITRE ATT&CK: G1027 View on attack.mitre.org
Aliases: Soldiers of Soloman, CyberAv3ngers
- First seen
- 2020-01-01 00:00:00
- Primary motivation
- sabotage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 21 (1 malicious)
- Last IoC activity
- 2026-09-12 13:17:30
- Profile updated
- 2026-08-31 08:19:28
Targeted industries: energy-and-utilities healthcare-and-pharmaceutical manufacturing
Targeted regions: country_code:il
Context
The CyberAv3ngers are a suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated APT group. The CyberAv3ngers have been known to be active since at least 2020, with disputed and false claims of critical infrastructure compromises in Israel. In 2023, the CyberAv3ngers engaged in a global targeting and hacking of the Unitronics Programmable Logic Controller (PLC) with Human-Machine Interface (HMI). This PLC can be found in multiple sectors, including water and wastewater, energy, food and beverage manufacturing, and healthcare. The most notable feature of this attack was the defacement of the devices user interface.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to CyberAv3ngers (G1027). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 175.110.121.41 | 2026-09-12 | 2 |
Reports & references
- CISA — Aa23 335A (report)
- MITRE ATT&CK — G1027 (report)
Attributed from
- Unitronics Defacement Campaign (campaign)
External references
- mitre-attack — G1027
- Soldiers of Soloman
- CISA AA23-335A IRGC-Affiliated December 2023
- misp-galaxy
- misp-galaxy