logo

IOCONTROL cyberweapon used to target infrastructure in the US and Isreael

ID: 3c32048e-3a35-56d1-ac5b-b9de800a0db5

STIX ID: report--3c32048e-3a35-56d1-ac5b-b9de800a0db5

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2024-12-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Claroty’s Team82 and reporting detail a custom, modular IoT/OT malware family named IOCONTROL used by an Iran-linked APT (CyberAv3ngers/IRGC-CEC) to target Israeli and U.S. infrastructure—notably Orpak and Gasboy fuel management/payment systems and various IP cameras, routers, PLCs and HMIs. The malware establishes persistence via a rc3.d boot script, communicates with MQTT C2 over TLS port 8883 with DoH for evasion, encrypts configs with AES-256-CBC, supports remote execution and scanning, and reportedly affected hundreds of devices with IoCs provided in the full analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.