New IOCONTROL malware used in critical infrastructure attacks
ID: fb8e3bd7-cc23-5629-89b5-218610cd3c8c
STIX ID: report--fb8e3bd7-cc23-5629-89b5-218610cd3c8c
Feed Name: Bleeping Computer
**IOCONTROL** is a modular nation-state level IoT/OT malware linked to the Iranian group CyberAv3ngers that has been observed compromising diverse critical-infrastructure devices (routers, PLCs/HMIs, fuel management systems like Orpak/Gasboy) in campaigns against Israel and the U.S.; Claroty recovered UPX-packed samples from a Gasboy payment terminal and documents capabilities such as persistent installation, MQTT C2 (port 8883) with DoH, AES-256-CBC configuration encryption, dynamic libc-based command execution, port scanning, and self-deletion, and provides IoCs to help defenders identify and block the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
