Iran-linked crew used custom 'cyberweapon' in US critical infrastructure attacks
ID: 288ed29d-6f60-572a-bd74-15fe7b16a5c6
STIX ID: report--288ed29d-6f60-572a-bd74-15fe7b16a5c6
Feed Name: The Register (Security)
Claroty Team82 and other sources attribute an Iranian government-linked crew (CyberAv3ngers) to campaigns deploying a custom backdoor named IOCONTROL against IoT and OT devices controlling water and fuel systems in the US and Israel. The malware was embedded in payment/fuel management terminals (OrPT/Gasboy) and impacted routers, PLCs, HMIs and other Linux-based IoT/OT devices from multiple vendors, enabling remote control, arbitrary code execution, port scanning, self-deletion, and potential disruption of services or theft of payment data; operators used MQTT for C2 and DNS over HTTPS for evasion, with active waves observed in mid‑Oct 2023–Jan 2024 and additional activity in July–August.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
