The Soldiers of Solomon (also spelled Soldiers of Soloman in some reporting) is a cyber persona associated with Iranian state-aligned cyber activity. Public reporting by government agencies and cybersecurity researchers indicates that the group is linked to the broader CyberAv3ngers operation, which has been attributed to actors affiliated with the Islamic Revolutionary Guard Corps (IRGC). The group has primarily focused on psychological operations, hacktivist-style messaging, and disruptive attacks against Israeli and Western organizations.
Unlike mature espionage groups such as APT33, APT34, or MuddyWater, Soldiers of Solomon appears to operate as a branding or influence persona that accompanies technical operations conducted by CyberAv3ngers. Numerous claims published through the groups Telegram channels have later been determined to be exaggerated or false, suggesting that information operations are a significant component of its activities.
Background
The group first gained attention through cyber operations targeting Israeli organizations. During the 2023 conflict in Israel, Soldiers of Solomon publicly claimed responsibility for compromising more than 50 servers, surveillance cameras, and smart city management systems. Subsequent investigations found that many of these claims could not be independently verified. Government agencies have since assessed the group as closely associated with the CyberAv3ngers operation.
CyberAv3ngers later shifted its focus toward operational technology (OT) environments, particularly Unitronics programmable logic controllers (PLCs) deployed in:
- Water and wastewater facilities
- Energy infrastructure
- Food manufacturing
- Healthcare
- Industrial control environments
These attacks primarily exploited internet-exposed devices configured with default credentials.
Primary Objectives
Observed objectives include:
- Disruption of critical infrastructure
- Political messaging
- Psychological influence operations
- Public defacement of industrial control systems
- Limited ransomware deployment claims
- Information warfare supporting Iranian geopolitical objectives
Technical Characteristics
Observed techniques include:
- Exploitation of internet-facing Unitronics PLCs
- Use of default credentials (commonly password 1111)
- HMI defacement
- OT disruption rather than data theft
- Telegram-based propaganda
- False or exaggerated breach claims
- Limited use of ransomware branding (Crucio)
MITRE ATT&CK maps CyberAv3ngers/Soldiers of Solomon activity to techniques including:
- Internet Accessible Device (T0883)
- Insecure Credentials (Default Credentials) (T1694.001)
- Denial of Service (T0814)
- Loss of Availability (T0826)
Infrastructure Targeting
Observed targets include:
- Unitronics Vision Series PLCs
- Human-Machine Interface (HMI) devices
- Water treatment control systems
- Wastewater facilities
- Energy management systems
- Smart city infrastructure
- Internet-exposed industrial controllers
Common Attack Indicators
Organizations should investigate for:
- Internet-exposed Unitronics PLCs
- Default administrative password 1111
- Unexpected HMI defacement
- Unauthorized PLC configuration changes
- Connections to the listed IP addresses
- Telegram references to CyberAv3ngers or Soldiers of Solomon
- Evidence of Crucio ransomware artifacts
