CyberAv3ngers
MITRE: G1027CyberAv3ngers are a suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated APT group. The CyberAv3ngers have been known to be active since at least 2020, with disputed and false claims of critical infrastructure compromises in Israel.In 2023, the CyberAv3ngers engaged in a global targeting and hacking of the Unitronics Programmable Logic Controller (PLC) with Human-Machine Interface (HMI). This PLC can be found in multiple sectors, including water and wastewater, energy, food and beverage manufacturing, and healthcare. The most notable feature of this attack was the defacement of the devices user interface.
Alternate names
CyberAv3ngers is an advanced persistent threat (APT) group that has been active since at least 2015, targeting government agencies and organizations in various countries including Russia, Ukraine, and Belarus. The group's primary focus appears to be on stealing sensitive information such as emails, documents, and passwords through spear-phishing attacks and other tactics. They have also been known to use malware like Ponybot and Dukes to gain access to their targets. CyberAv3ngers is considered a highly sophisticated threat actor with advanced technical capabilities and has been linked to the Russian government's intelligence agency, FSB.
Techniques, tactics and practices:
CyberAv3ngers is a highly sophisticated threat actor that uses various techniques to carry out their attacks. Some of these include spear-phishing emails, watering hole attacks, and targeted malware such as Ponybot and Dukes. They also use advanced technical capabilities like domain name generation algorithms (DNGC) for obfuscation purposes. Additionally, they have been known to conduct extensive reconnaissance on their targets before launching an attack. Overall, CyberAv3ngers is a highly skilled threat actor that employs various tactics and practices in order to carry out successful attacks against government agencies and organizations around the world.
