logo

New IOCONTROL malware used in critical infrastructure attacks

ID: fb8e3bd7-cc23-5629-89b5-218610cd3c8c

STIX ID: report--fb8e3bd7-cc23-5629-89b5-218610cd3c8c

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-12-12

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

**IOCONTROL** is a modular nation-state level IoT/OT malware linked to the Iranian group CyberAv3ngers that has been observed compromising diverse critical-infrastructure devices (routers, PLCs/HMIs, fuel management systems like Orpak/Gasboy) in campaigns against Israel and the U.S.; Claroty recovered UPX-packed samples from a Gasboy payment terminal and documents capabilities such as persistent installation, MQTT C2 (port 8883) with DoH, AES-256-CBC configuration encryption, dynamic libc-based command execution, port scanning, and self-deletion, and provides IoCs to help defenders identify and block the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.