logo

Iran-linked crew used custom 'cyberweapon' in US critical infrastructure attacks

ID: 288ed29d-6f60-572a-bd74-15fe7b16a5c6

STIX ID: report--288ed29d-6f60-572a-bd74-15fe7b16a5c6

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2024-12-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Claroty Team82 and other sources attribute an Iranian government-linked crew (CyberAv3ngers) to campaigns deploying a custom backdoor named IOCONTROL against IoT and OT devices controlling water and fuel systems in the US and Israel. The malware was embedded in payment/fuel management terminals (OrPT/Gasboy) and impacted routers, PLCs, HMIs and other Linux-based IoT/OT devices from multiple vendors, enabling remote control, arbitrary code execution, port scanning, self-deletion, and potential disruption of services or theft of payment data; operators used MQTT for C2 and DNS over HTTPS for evasion, with active waves observed in mid‑Oct 2023–Jan 2024 and additional activity in July–August.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.