CyberAv3ngers: From Infrastructure Hacks to Propaganda Machines in the Iran-Israel Cyber War

CyberAv3ngers: From Infrastructure Hacks to Propaganda Machines in the Iran-Israel Cyber War

CyberAv3ngers is a cyber threat group engaged in Iran-Israel conflict, blending real cyberattacks with psychological operations and propaganda to influence public perception and sow fear. Their activities range from hijacking industrial control systems to orchestrating narrative-driven campaigns supported by suspected ties to Iran’s IRGC-Cyber Electronic Command. #CyberAv3ngers #IRGCCEC #IOCONTROL

Keypoints

  • CyberAv3ngers emerged from obscure defacement groups and evolved into sophisticated operators combining cyber sabotage with psychological warfare.
  • The group falsely claimed to hack Israel’s Dorad power station in 2023 by recycling older leaked data to amplify fear and distrust.
  • Between 2023 and 2024, they conducted multiple confirmed cyber intrusions targeting industrial control systems in the US, including water utilities and fuel terminals.
  • IOCONTROL, a custom Linux-based malware employing encrypted MQTT communication, played a central role in their persistent access and remote attacks.
  • CyberAv3ngers uses symbolic domain registrations and staged online content to reinforce their digital persona and ideological influence.
  • The U.S. government attributes part of CyberAv3ngers’ campaigns to IRGC-CEC operatives, sanctioning key individuals such as Mahdi Lashgarian, suspected to be the malware operator “Mr. Sul”.
  • Retaliatory pro-Israel hacktivists have publicly doxxed Lashgarian, marking a personal dimension in the cyber conflict between Iran and Israel.

MITRE Techniques

  • [T1499] Endpoint Denial of Service – CyberAv3ngers conducted DDoS attacks on Israeli websites to support psychological operations (“The only actual activity was a denial-of-service (DDoS) attack on the Dorad website”).
  • [T1566] Phishing and Social Engineering – Use of Telegram channels to spread threats, slogans, repurposed defacements, and propaganda simulating recent operations (“operates a Telegram channel not just for updates, but as a staged information environment”).
  • [T1210] Exploitation for Defense Evasion – Use of custom IOCONTROL malware enabling encrypted MQTT communication for stealthy command and control (“custom Linux-based malware tool known as IOCONTROL, which enabled persistent access, remote command execution, and stealthy communication via encrypted MQTT channels”).
  • [T1071] Application Layer Protocol – MQTT used as secure communication channel for malware control (“stealthy communication via encrypted MQTT channels”).

Indicators of Compromise

  • [Domain Names] Symbolic domains registered to reinforce CyberAv3ngers’ digital presence – cyberav3ngers.com, cyberav3ngers.org, cyberav3ngers.net.
  • [File Hashes] Recycled leaked data from 2022 Moses Staff incident used in false Dorad hack claims (specific hashes not provided, but referenced as linked to Moses Staff leak).
  • [File Names] IOCONTROL Linux-based malware used in attacks – no specific file names provided.


Read more: https://dti.domaintools.com/cyberav3ngers-from-infrastructure-hacks-to-propaganda-machines-in-the-iran-israel-cyber-war/