By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: CyberAv3ngers: The Iranian Saboteurs Hacking Water and Gas Systems Worldwide
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release

xAI explains Grok’s Nazi meltdown, as Tesla puts Elon’s bot in its cars

News Room News Room 13 July 2025
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > CyberAv3ngers: The Iranian Saboteurs Hacking Water and Gas Systems Worldwide
News

CyberAv3ngers: The Iranian Saboteurs Hacking Water and Gas Systems Worldwide

News Room
Last updated: 15 April 2025 03:14
By News Room 5 Min Read
Share
SHARE

That initial wave of CyberAv3ngers hacking, both real and fabricated, appears to have been part of a tit-for-tat with another highly aggressive hacker group that is widely believed to work on behalf of Israeli military or intelligence agencies. That rival group, known as Predatory Sparrow, repeatedly targeted Iranian critical infrastructure systems while similarly hiding behind a hacktivist front. In 2021, it disabled more than 4,000 Iranian gas stations across the country. Then, in 2022, it set a steel mill on fire in perhaps the most destructive cyberattack in history. Following CyberAv3ngers’ late 2023 hacking campaign, and missile launches against Israel by Iranian-backed Houthi rebels, Predatory Sparrow retaliated again by knocking out thousands of Iran’s gas stations in December of that year.

“Khamenei!” Predatory Sparrow wrote on X, referring to the supreme leader of Iran in Farsi. “We will react against your evil provocations in the region.”

Predatory Sparrow’s attacks have been tightly focused on Iran. But CyberAv3ngers hasn’t limited itself to Israeli targets, or even Israeli-made devices used in other countries. In April and May of last year, Dragos says, the group breached a US oil and gas firm—Dragos declined to name which one—by compromising the company’s Sophos and Fortinet security appliances. Dragos found that in the months that followed, the group was scanning the internet for vulnerable industrial control system devices, as well as visiting the websites of those devices’ manufacturers to read about them.

Following its late 2023 attacks, the US Treasury sanctioned six IRGC officials that it says were linked to the group, and the State Department put its $10 million bounty on their heads. But far from being deterred, CyberAv3ngers has instead shown signs of evolving into a more pervasive threat.

Last December, Claroty revealed that CyberAv3ngers had infected a wide variety of industrial control systems and internet-of-things (IOT) devices around the world using a piece of malware it developed. The tool, which Claroty calls IOControl, was a Linux-based backdoor that hid its communications in a protocol known as MQTT used by IOT devices. It had been planted on everything from routers to cameras to industrial control systems. Dragos says it found devices infected by the group worldwide, from the US to Europe to Australia.

According to Claroty and Dragos, the FBI took control of the command-and-control server for IOControl at the same time as Claroty’s December report, neutralizing the malware. (The FBI didn’t respond to WIRED’s request for comment about the operation.) But CyberAv3ngers’ hacking campaign nonetheless shows a dangerous evolution in the group’s tactics and motives, according to Noam Moshe, who tracks the group for Claroty.

“We’re seeing CyberAv3ngers moving from the world of opportunistic attackers where their whole goal was spreading a message into the realm of a persistent threat,” Moshe says. In the IOControl hacking campaign, he adds, “they wanted to be able to infect all kinds of assets that they identify as critical and just leave their malware there as an option for the future.”

Exactly what the group might have been waiting for—possibly some strategic moment when the Iranian government could gain a geopolitical advantage from causing widespread digital disruption—is far from clear. But the group’s actions suggest that it’s no longer seeking to merely send a message of protest against Israeli military actions. Instead, Moshe argues, it’s trying to gain the ability to disrupt foreign infrastructure at will.

“This is like a red button on their desk. At a moment’s notice they want to be able to attack many different segments, many different industries, many different organizations, however they choose,” he says. “And they’re not going away.”

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Resident Evil Survival Unit Is a ‘Global Multiplayer Experience’ Set in a Parallel Universe Featuring Leon, Jill, and the Resi 4 Merchant

News Room News Room 12 July 2025
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

Why Are There No Good Superman Games?

Superman may be widely regarded as one of the greatest pop culture icons of all…

12 July 2025

The Best Deals Today: Apple AirPods Pro 2, Split Fiction, Kingdom Come: Deliverance II, and More

We've rounded up the best deals for Saturday, July 12, below, so don't miss out…

12 July 2025

Of Ash and Steel Is an Old-School RPG With On-the-Job Training for Fantasy Adventurers

Dispatched by the crown as part of a secret expedition to a remote island part…

12 July 2025
Gaming

20 Years Ago This Losing Racehorse Charmed Japan — Now an Anime Horse-Girl Game’s Western Launch Has Brought Her a New Army of Fans

Umamusume: Pretty Derby, the Japanese mobile game in which you raise anime horse-girls, has brought Japan’s most unsuccessful racehorse a second boom in popularity following its western launch on Steam…

News Room 12 July 2025

Your may also like!

News

Security News This Week: 4 Arrested Over Scattered Spider Hacking Spree

News Room 12 July 2025
News

I’ve been using Amazon’s Alexa Plus for one day — here are my first impressions

News Room 12 July 2025
News

Review: Timekettle T1 Handheld Translator

News Room 12 July 2025
News

The best Amazon Prime Day deals you can still get

News Room 12 July 2025

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?