Cyberav3ngers: The Way of Water
Welcome to Memetic Warfare.
Readers of the blog that follow mainstream media may have heard that Iran is suspected of hacking US water infrastructure in multiple states lately.
This is also a great opportunity for those who haven’t read it to read DTI’s post on attacks on water infra, available here.
This attack comes about a week after CISA and partners published an update to a past threat advisory of Iran/IRGC-linked attacks on PLCs in critical infrastructure:
What makes this interesting is that it is almost the same type of operation done by the IRGC APT cyberav3ngers, which targeted PLCs in US water infrastructure, hitting over 70 targets as per previous CISA announcements. They were since sanctioned and presumably hit back somehow, and they scrambled.
They later merged with APT Iran, another Iran-linked APT group (for more background and the interesting history there check out the post below), claiming to hit US gas stations.
VirusBearSparrow
Welcome to Memetic Warfare. This is a long and special post, so buckle up buckaroos.
Because they’ve been working together/are now the same group, it made sense to check up on them. APT IRAN hasn’t been active for a while, only reviving its channel on August 2nd:
They then began targeting civilian sites in Turkey and selling the data online:
So, APT IRAN isn’t doing anything public related to the attacks in the US, though we know that they’re tied to the cyberav3ngers now. Let’s check in on Mr. Soul, a known persona run by one of the cyberav3nger operators.
He has a long-running group and channel which have been up for a while. Interestingly, he denies the claims and says that he and the cyberav3ngers will announce attacks officially on his channel and soon on theirs:
He then shares a post from a new group for the cyberav3ngers - note how the timing here overlaps well with APT IRAN starting up again - in which cyberav3ngers denies involvement:
It’s unclear to me what’s going on. The ongoing attacks are very similar in terms of TTPs, but we don’t have the usual amplification and credit-taking by APT IRAN or cyberav3ngers that we had in the past and that you’d expect from Iranian groups.
Perhaps this signals a change in strategy - from taking credit immediately and trying to use that angle to denying the attack and trying to maximize confusion. Who knows! The confusion angle is working pretty well in the US as it continues to be covered as a more mysterious threat.
I’m sure that we’ll know more soon, especially if/when IoCs are every published. Thanks for reading.











