CyberAv3ngers is a cyber threat group engaged in Iran-Israel conflict, blending real cyberattacks with psychological operations and propaganda to influence public perception and sow fear. Their activities range from hijacking industrial control systems to orchestrating narrative-driven campaigns supported by suspected ties to Iran’s IRGC-Cyber Electronic Command. #CyberAv3ngers #IRGCCEC #IOCONTROL
Keypoints
- CyberAv3ngers emerged from obscure defacement groups and evolved into sophisticated operators combining cyber sabotage with psychological warfare.
- The group falsely claimed to hack Israel’s Dorad power station in 2023 by recycling older leaked data to amplify fear and distrust.
- Between 2023 and 2024, they conducted multiple confirmed cyber intrusions targeting industrial control systems in the US, including water utilities and fuel terminals.
- IOCONTROL, a custom Linux-based malware employing encrypted MQTT communication, played a central role in their persistent access and remote attacks.
- CyberAv3ngers uses symbolic domain registrations and staged online content to reinforce their digital persona and ideological influence.
- The U.S. government attributes part of CyberAv3ngers’ campaigns to IRGC-CEC operatives, sanctioning key individuals such as Mahdi Lashgarian, suspected to be the malware operator “Mr. Sul”.
- Retaliatory pro-Israel hacktivists have publicly doxxed Lashgarian, marking a personal dimension in the cyber conflict between Iran and Israel.
MITRE Techniques
- [T1499] Endpoint Denial of Service – CyberAv3ngers conducted DDoS attacks on Israeli websites to support psychological operations (“The only actual activity was a denial-of-service (DDoS) attack on the Dorad website”).
- [T1566] Phishing and Social Engineering – Use of Telegram channels to spread threats, slogans, repurposed defacements, and propaganda simulating recent operations (“operates a Telegram channel not just for updates, but as a staged information environment”).
- [T1210] Exploitation for Defense Evasion – Use of custom IOCONTROL malware enabling encrypted MQTT communication for stealthy command and control (“custom Linux-based malware tool known as IOCONTROL, which enabled persistent access, remote command execution, and stealthy communication via encrypted MQTT channels”).
- [T1071] Application Layer Protocol – MQTT used as secure communication channel for malware control (“stealthy communication via encrypted MQTT channels”).
Indicators of Compromise
- [Domain Names] Symbolic domains registered to reinforce CyberAv3ngers’ digital presence – cyberav3ngers.com, cyberav3ngers.org, cyberav3ngers.net.
- [File Hashes] Recycled leaked data from 2022 Moses Staff incident used in false Dorad hack claims (specific hashes not provided, but referenced as linked to Moses Staff leak).
- [File Names] IOCONTROL Linux-based malware used in attacks – no specific file names provided.