Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Cyber Av3ngers

🇮🇷Cyber Av3ngers

🇮🇷 Cyber Av3ngers is a tracked threat actor in the Clankerusecase corpus. Attributed to IR. Primary motivation: Hacktivist. We map 10 detection use cases to this actor across 15 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-21 to 2026-07-21.

high 1
View full actor card → All threat actors
10Use cases
1Articles
15Techniques
0IOCs

Known aliases

Cyber Av3ngersCyberAvengersIRGC-CEC

Top techniques

All other tracked techniques

Detection use cases (10)

Cyber Av3ngers Unitronics PLC exploitation over TCP/20256 (default-credential OT takeover) AI · profile SΣDD Cyber Av3ngers remote-access-tool staging on OT-adjacent Windows hosts (T1219 post-exploit foothold) AI · profile SΣDD Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) Bespoke Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) Bespoke AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal Trusted vendor binary / installer launching unusual children Internal

Threat-intel articles (1)