Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Cyber Av3ngers

🇮🇷Cyber Av3ngers

🇮🇷 Cyber Av3ngers is a tracked threat actor in the Clankerusecase corpus. Attributed to IR. Primary motivation: Hacktivist. We map 14 detection use cases to this actor across 16 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-07-21 to 2026-07-29.

crit 1high 1
View full actor card → All threat actors
14Use cases
2Articles
16Techniques
0IOCs

Known aliases

Cyber Av3ngersCyberAvengersIRGC-CEC

Top techniques

All other tracked techniques

Detection use cases (14)

Cyber Av3ngers Unitronics PCOM (TCP/20256) PLC targeting AI · profile SΣDD Cyber Av3ngers IOControl/OrpaCrab MQTT C2 with DoH resolution AI · profile SDD Asset exposure — vulnerability matches article CVE(s) Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) Bespoke Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) Bespoke AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal

Threat-intel articles (2)

Tracked indicators

CVEs (3)

CVE-2021-22681 CVE-2023-3595 CVE-2024-6242