Cyber Avengers
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Cyber Avengers, also tracked as CyberAv3ngers, is a threat actor publicly linked to Iran and known for using multiple aliases in its communications. The group operates primarily through Telegram channels where it announces responsibility for various incidents and shares purported evidence. Public reporting consistently associates the actor with an Iranian nexus, although no formal state sponsorship has been explicitly confirmed in the sources provided.
The actor’s observed targeting focuses on critical infrastructure sectors, particularly water utilities and energy facilities, with a geographic emphasis on the United States and Israel. In the United States, the group has been linked to disruptions affecting water management districts in Florida and a municipal water authority in Pennsylvania, where isolated pump‑station networks were compromised and messages were displayed. In Israel, the actor claimed a distributed denial‑of‑service attack against the Bazan Group, the nation’s largest oil refinery, and alleged access to supervisory control and data acquisition (SCADA) systems. These actions appear aimed at causing operational disruption and generating publicity rather than pursuing financial gain, as no verifiable ransomware deployment or monetary extortion has been attributed to the group in the cited incidents.
Reported tactics, techniques, and procedures include the use of distributed denial‑of‑service to overwhelm online services, the claimed exploitation of firewall devices—specifically a Check Point unit associated with the Bazan Group—and the alleged acquisition and leakage of SCADA screenshots to demonstrate alleged access to industrial control systems. The actor also highlights its focus on Israeli‑linked technology, such as Unitronics components used in water‑purification pumps, suggesting a pattern of targeting supply‑chain or third‑party assets tied to perceived adversaries. All of these TTPs are drawn from statements made by the group itself; independent verification of the claimed exploits or data leaks remains lacking in the available sources.
Among the campaigns most frequently referenced in open‑source reporting are the November 2023 incident involving the St. Johns River Water Management District, the October 2023 compromise of the Municipal Water Authority of Aliquippa, and the June‑July 2023 DDoS operation against the Bazan Group’s websites. The actor has also asserted responsibility for unrelated events such as the 2021 Haifa Bay petrochemical‑plant fires and a 2020 series of alleged attacks on Israeli railway stations, though these claims have not been substantiated by independent investigators. These examples illustrate the actor’s recurring focus on disrupting essential services and amplifying its messaging through high‑profile targets.
Incidents
Attributed incidents are available to members.
3 incidents