Islamic Revolutionary Guard Corps Cyber
The Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC), also referenced in public material as the IRGC Electronic Warfare and Cyber Defense Organization, is a state-linked Iranian cyber command structure tied to malicious cyber operations against critical infrastructure, government entities, and private-sector organizations in the United States, Israel, and other countries. Public reporting and sanctions actions indicate that the IRGC-CEC does not operate only through a single public-facing brand. Instead, it appears to use a layered operational model that includes official personnel, front companies, contractor-like cyber staff, and branded personas such as CyberAv3ngers to create distance between the state organization and the visible operation.
The most visible and best-documented IRGC-CEC-linked activity in open sources is the targeting of internet-exposed operational technology (OT) devices, especially Israeli-made Unitronics PLC/HMI systems, using weak or default credentials and public exposure to achieve defacement and operational impact. That campaign is strategically important not because it demonstrated exquisite stealth or novel exploitation, but because it showed willingness to touch civilian critical infrastructure and public services in a way that carried disruptive and psychological value disproportionate to the simplicity of the intrusion path.
Public reporting in 2024 and 2025 further broadened the picture. Treasury reporting described IRGC-CEC use of front companies in support of cyber operations. Claroty linked an Iran-affiliated campaign tied to CyberAv3ngers with IOCONTROL, a modular Linux-based malware framework used against IoT/OT systems. OpenAI reported that accounts attributed to CyberAv3ngers used AI models for reconnaissance into PLCs, scripting, vulnerability research, and post-compromise questions. Taken together, these strands suggest an organization that combines state direction, pragmatic operator tradecraft, influence amplification, and selective disruptive intent.
INFERENCE (confidence: high): IRGC-CEC is best understood as a state cyber command-and-control function that can flex between espionage support, disruptive critical-infrastructure operations, influence-oriented hacktivist branding, and contracted or front-company-enabled cyber execution.
ATT&CK