WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) A Deep Dive into the Iranian-Backed CyberAv3ngers
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) A Deep Dive into the Iranian-Backed CyberAv3ngers

TLP:CLEAR

Author: Chase Snow

Created: Wednesday, April 16, 2025 - 16:08

Categories: Cybersecurity, OT-ICS Security, Security Preparedness

Summary: Wired published a recent article featuring a deep dive into the Iranian state-backed hacktivist group known as the CyberAv3ngers, stating “The group known as CyberAv3ngers has, in the last year and a half, proven to be the Iranian government’s most active hackers focused on industrial control systems. Its targets include water, wastewater, oil and gas, and many other types of critical infrastructure.” The article provides an overview of the group’s history targeting critical infrastructure, giving an analysis of their tactics and capabilities.

Analyst Note: The CyberAv3ngers are best known in the water sector for compromising and defacing Unitronics PLCs across several U.S.-based water and wastewater utilities, like in the incident at the Municipal Water Authority of Aliquippa in November 2023. These attacks brought awareness to glaring gaps in the security of ICS devices  and demonstrated how geopolitical conflicts can have direct effects on the water and wastewater sector.

Wired’s analysis indicates that the CyberAv3ngers are recognized as a serious state-backed threat actor. While no recent attacks linked to the group have targeted the water sector, this last December saw the group employing sophisticated tactics, including the development of the IOControl malware used to infiltrate industrial control systems and internet-of-things (IOT) devices globally. Members are encouraged to remain vigilant by reviewing the group’s tactics and ensuring PLC devices are properly secured.

Original Source: https://www.wired.com/story/cyberav3ngers-iran-hacking-water-and-gas-industrial-systems/

Additional Reading:

  • Inside a New IoT/OT Cyberweapon: IOCONTROL

Mitigation Recommendations:

  • WaterISAC Advisory: (TLP:CLEAR) CISA and Partners Confirm Additional Activity into Exploitation of Unitronics PLCs Across the U.S. Water and Wastewater Sector

Related WaterISAC PIRs: 6, 6.1, 7, 7.1, 9, 10, 10.2, 12

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar