🇮🇷Cyber Av3ngers
🇮🇷 Cyber Av3ngers is a tracked threat actor in the Clankerusecase corpus. Attributed to IR. Primary motivation: Hacktivist. We map 14 detection use cases to this actor across 16 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-07-21 to 2026-07-29.
crit 1high 1
14Use cases
2Articles
16Techniques
0IOCs
Known aliases
Cyber Av3ngersCyberAvengersIRGC-CEC
Top techniques
All other tracked techniques
T1036.005 · Match Legitimate Resource Name or LocationT1059.001 · PowerShellT1059.005 · Visual BasicT1072 · Software Deployment ToolsT1195.002 · Compromise Software Supply ChainT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1566.001 · Spearphishing AttachmentT1574.002 · T1574.002T1574.014 · AppDomainManager
Detection use cases (14)
Cyber Av3ngers Unitronics PCOM (TCP/20256) PLC targeting Cyber Av3ngers IOControl/OrpaCrab MQTT C2 with DoH resolution Asset exposure — vulnerability matches article CVE(s) Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process RMM tool installed by non-IT user — remote-access utility for hands-on-keyboardThreat-intel articles (2)
Tracked indicators
CVEs (3)
CVE-2021-22681 CVE-2023-3595 CVE-2024-6242