CyberAv3ngers

☆ pin
Also known as Storm-0784, CL-STA-1128, Hydro Kitten, Shahid Kaveh Group, Bauxite, UNC5691
Reports
8
First seen
Mar 12, 2026
Last seen
Jul 29, 2026
Motivation
Sabotage, Hacktivism, Espionage

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×1
×3
United States×3
Israel×1

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1486 Data Encrypted for Impact ×4T1566 Phishing ×4T1498 Network Denial of Service ×3T1570 Lateral Tool Transfer ×2T1003 OS Credential Dumping ×2T1566.002 Phishing: Spearphishing Link ×2T1078 Valid Accounts ×2T1110 Brute Force ×2T1219 Remote Access Software ×2T1021.001 Remote Services: RDP ×2T1195 Supply Chain Compromise ×2T1005 Data from Local System ×2

Indicators

ip_v4 ×23domain ×3hash_sha1 ×2filename ×1registry_key ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.