Full Report
More than 30 facilities disrupted in 'coordinated cyberattack,' though officials have yet to name a culprit
Analysis Summary
# Threat Actor: CyberAv3ngers
## Attribution & Identity
* **Identification:** An Iran-linked "faux hacktivist" outfit.
* **Aliases/Associations:** Widely believed to be linked to Iran’s Islamic Revolutionary Guard Corps (IRGC), specifically the **IRGC-CEC** (Cyber-Electronic Command) division.
* **Nature:** Originally emerged as a propaganda persona before transitioning into active disruptive operations.
## Activity Summary
* **Minnesota Water Systems (July 2026):** Suspected of a coordinated cyberattack disrupting more than 30 community water facilities. The attacks targeted Operational Technology (OT) systems, leading to a state of emergency in some municipalities (e.g., Maple Plain) and water usage restrictions in others (e.g., Braham).
* **Ongoing 2026 Campaign:** Increased targeting of US critical infrastructure using Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens equipment.
* **Historical Campaigns:**
* **November 2023:** Compromised Municipal Water Authority of Aliquippa, Pennsylvania, and at least 74 other Unitronics PLCs globally.
* **2020–2022:** Conducted propaganda operations and claimed fabricated attacks on Israeli infrastructure.
## Tactics, Techniques & Procedures
* **Exploitation of Defaults:** Frequent use of default passwords to gain access to Programmable Logic Controllers (PLCs).
* **OT/IoT Targeting:** Focus on disrupting Industrial Control Systems (ICS) and Operational Technology.
* **Remote Access Abuse:** Leveraging poorly secured remote-access software such as **TeamViewer** and **AnyDesk** to bypass enterprise security controls.
* **Web Exposure:** Identifying and targeting PLCs directly exposed to the public internet.
* **Lateral Movement:** Exploiting poor segmentation between IT and OT environments to spread intrusions.
* **AI-Assisted Development:** Known to have used LLMs (ChatGPT) for malware development and reconnaissance.
* **Defacement:** Overwriting PLC HMI screens with anti-Israel propaganda and political messages.
## Targeting
* **Sectors:** Water and Wastewater Systems (WWS), Energy Providers, Government Facilities, and general Critical Infrastructure.
* **Geography:** Primarily United States, Israel, United Kingdom, and Ireland.
* **Victims:** Specifically small, rural municipal facilities with limited cybersecurity resources. Mentioned entities include:
* Minnesota Department of Health (affected facilities)
* City of Braham, MN
* Maple Plain, MN
* Municipal Water Authority of Aliquippa, PA
## Tools & Infrastructure
* **Malware:** **IOCONTROL** – a specialized malware kit developed between 2024–2025 for OT and IoT disruption.
* **Hardware Targets:**
* Unitronics Vision Series PLCs
* Rockwell Automation / Allen-Bradley PLCs
* Schneider Electric equipment
* Siemens equipment
* **Software:** Usage of legitimate remote administration tools (RATs) like TeamViewer and AnyDesk for unauthorized access.
## Implications
CyberAv3ngers represents a persistent threat to "low-hanging fruit" within critical infrastructure. Their shift from propaganda to the deployment of dedicated OT malware (IOCONTROL) indicates an evolving capability to cause physical disruptions. While current attacks have primarily resulted in temporary operational outages and limited public impact, the focus on small municipal utilities highlights a strategic vulnerability where decentralized, underfunded facilities can be targeted en masse to create regional instability.
## Mitigations
* **Password Hygiene:** Change all default credentials on PLCs and OT hardware immediately.
* **Network Segmentation:** Implement strict hardware/software segmentation between IT and OT networks to prevent lateral movement.
* **Remote Access Security:** Disable or strictly control remote-access software (TeamViewer, AnyDesk) and require Multi-Factor Authentication (MFA).
* **Asset Exposure Management:** Ensure PLCs and ICS components are not directly reachable from the public internet; use VPNs or industrial gateways for necessary remote monitoring.
* **Monitoring:** Implement security monitoring for "invisible" attack surfaces created by remote-access tools.