IRGC Cyber Campaigns Against U.S. and Israeli Critical Infrastructure
- Actor Motivations: Disinformation,Sabotage
- Attack Vectors: Compromised Credentials,Defacement,Security Misconfiguration
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
Iranian IRGC-affiliated cyber actors, using the persona “CyberAv3ngers,” have been actively targeting and compromising Unitronics Vision Series programmable logic controllers (PLCs) used in the Water and Wastewater Systems (WWS) Sector across multiple U.S. states. These attacks, observed since at least November 2023, involve compromising default credentials and defacing the PLCs, potentially rendering them inoperative. The actors also targeted Israeli PLCs in various sectors like water, energy, and distribution. Additionally, they falsely claimed responsibility for cyberattacks on critical infrastructure in Israel and have connections to the Soldiers of Solomon group. The attacks leverage internet-facing applications and involve tactics like data destruction, resource hijacking, and potential use of ransomware.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Unitronics Unitronics is a company founded in 1989 that specializes in the design, manufacture, and marketing of advanced control and automation solutions. The company's extensive offering includes a complete line of PLCs with integrated HMI, a full line of VFDs, a broad array of I/Os and complementary devices, as well as programming software for all aspects of control, motion, HMI, and communications. Unitronics has been targeted by CyberAv3ngers with abusive purposes. | Verified |
| Sector | Energy | Verified |
| Sector | Transportation | Verified |
| Region | Israel | Verified |
| Region | United States | Verified |
Extracted IOCs
- ba284a4b508a7abd8070a427386e93e0
- 66ae21571faee1e258549078144325dc9dd60303
- 440b5385d3838e3f6bc21220caa83b65cd5f3618daea676f271c3671650ce9a3
- 178[.]162.227.180
- 185[.]162.235.206
Tip: 5 related IOCs (2 IP, 0 domain, 0 URL, 0 email, 3 file hash) to this threat have been found.
FAQs
CyberAv3ngers Exploitation of Industrial Control Systems
Iranian state-affiliated cyber actors gained unauthorized access to industrial control devices known as Programmable Logic Controllers (PLCs). Once inside, the attackers defaced the user screens of these controllers with anti-Israel messages, rendering the equipment inoperative and disrupting operational visibility.
The attack was conducted by "CyberAv3ngers," a cyber persona linked to the Iranian Government Islamic Revolutionary Guard Corps (IRGC), a designated foreign terrorist organization. CyberAv3ngers has claimed attacks on critical infrastructure since 2020 and works in connection with another IRGC-linked cyber group known as Soldiers of Solomon.
The campaign targeted facilities operating Israeli-manufactured Unitronics Vision Series PLCs, focusing heavily on Water and Wastewater Systems (WWS) facilities across several U.S. states and Israel, as well as energy, healthcare, and manufacturing facilities. The threat actors explicitly targeted these devices because they were manufactured in Israel and were left exposed to the open internet.
The actors scanned the internet for publicly accessible Unitronics PLCs operating on standard ports. They gained control simply by using the manufacturer's default factory passwords, which had not been changed by the equipment operators.
This is a targeted campaign aimed at organizations using specific, internet-exposed Unitronics PLCs with default settings. However, because these devices are widely deployed across multiple critical infrastructure sectors, any exposed unit using default credentials remains at high risk.
Organizations should immediately change all factory default credentials on their industrial control equipment and disconnect PLCs from direct exposure to the public internet. Security teams should also inspect control networks for any deeper unauthorized activity and review mitigation guidance published by CISA and partner cybersecurity agencies.