MITRE ATT&CK G1028

IRGC Cyber-Electronic Command

View MITRE Group Page ↗
Aliases: CyberAv3ngers, Shahid Shoushtari, Cotton Sandstorm
Official Attribution Source: U.S. Department of Justice (W.D. Pa.) & CISA Advisory AA23-335A

Key Facts

Jurisdiction
Islamic Republic of Iran
Geographic origin
Cases
1
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: Islamic Republic of Iran.
  • ATT&CK Group Reference: G1028 (IRGC Cyber-Electronic Command).
  • Linked to 1 primary court prosecution records.
  • Identified 0 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to IRGC Cyber-Electronic Command Technique frequencies extracted from verified indictments for IRGC Cyber-Electronic Command. T1078 Valid Accounts 1 incidents T1485 Data Destruction 1 incidents
Technique frequencies extracted from verified indictments for IRGC Cyber-Electronic Command.
ATT&CK Techniques Mapped to IRGC Cyber-Electronic Command
Technique Frequency
T1078 Valid Accounts 1 incidents
T1485 Data Destruction 1 incidents

Prosecution Cases Attributed to This Actor

fugitive 2024-09-24

U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)

Indictment of members of the Iranian Islamic Revolutionary Guard Corps Cyber-Electronic Command who compromised Israeli-made Unitronics programmable logic controllers (PLCs) at American municipal water facilities.

2 techniques View case →
OPERATIONAL DEFENSE

Targeted Defensive Hardening for IRGC Cyber-Electronic Command

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.