CyberAv3ngers
2 briefings · first covered 4/18/2026 · last covered 5/17/2026
Exploitable Vulnerabilities, Prioritized
Sorted by CISA KEV status and EPSS exploit probability, same signals as the dashboard.
Indicators of Compromise
Subscribe to unlock this actor's full IOC list
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Attribution & Known Techniques
Matched to CyberAv3ngers in MITRE ATT&CK.
6 MITRE ATT&CK techniques for this actor
This is a paid platform feature — not included with a free email subscription. It requires an active team account.
Coverage Timeline
5/17/2026 · KNOW YOUR ENEMY
CyberAv3ngers: The IRGC Unit Operating Inside US Water and Energy Infrastructure Right Now
CyberAv3ngers IRGC group exploits Rockwell PLCs across US critical infrastructure. Here is how they operate and how to detect them.
4/18/2026 · KNOW YOUR ENEMY
CyberAv3ngers Breached 75+ US Water & Energy PLCs, And They're Still Inside
CyberAv3ngers: Iran's IRGC-linked APT inside US water, energy and government PLCs, CVE-2021-22681 CVSS 9.8 has no patch and they are escalating.
Not yet tracked for this actor
- CrowdStrike Falcon / SentinelOne Deep Visibility-specific query syntax — hunting queries above (if any) are Microsoft Defender/Sentinel KQL
- File transfer and exfiltration services used
- Hunting queries — no FalconFriday rule matched this actor's known techniques