IOCONTROL cyberweapon used to target infrastructure in the US and Isreael
ID: 3c32048e-3a35-56d1-ac5b-b9de800a0db5
STIX ID: report--3c32048e-3a35-56d1-ac5b-b9de800a0db5
Feed Name: Security Affairs
Claroty’s Team82 and reporting detail a custom, modular IoT/OT malware family named IOCONTROL used by an Iran-linked APT (CyberAv3ngers/IRGC-CEC) to target Israeli and U.S. infrastructure—notably Orpak and Gasboy fuel management/payment systems and various IP cameras, routers, PLCs and HMIs. The malware establishes persistence via a rc3.d boot script, communicates with MQTT C2 over TLS port 8883 with DoH for evasion, encrypts configs with AES-256-CBC, supports remote execution and scanning, and reportedly affected hundreds of devices with IoCs provided in the full analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
