IOCONTROL is a custom Linux-based malware platform used in attacks against Internet of Things, operational technology, and SCADA-adjacent environments. It is widely attributed to CyberAv3ngers, a threat actor assessed to operate on behalf of Iran’s IRGC Cyber-Electronic Command, and has been used against civilian critical infrastructure in Israel and the United States, including fuel-management environments and other embedded industrial or edge devices.
The malware is best characterized as a modular backdoor for embedded Linux systems, including ARM-based devices, with configuration options that allow adaptation to different vendors, architectures, and device roles. Reported targets include routers, firewalls, IP cameras, PLCs, HMIs, and fuel-management systems from multiple industrial and networking vendors. IOCONTROL has been observed in campaigns affecting fuel distribution infrastructure and is assessed as part of a broader Iranian effort to move from opportunistic PLC defacement and default-credential abuse toward persistent implant-based access in OT-adjacent environments.
IOCONTROL supports persistent execution at boot through Linux init-style startup mechanisms and maintains encrypted configuration data. Its command-and-control architecture uses MQTT over TLS, with device-specific identification and structured tasking, and it has also been reported to use DNS over HTTPS for covert name resolution. Supported operator functions include host profiling, arbitrary operating-system command execution, command output return, internal port scanning, executable verification, and self-deletion for defense evasion. These capabilities enable post-compromise control, reconnaissance, and potential disruption or data theft from affected environments.
The malware has been linked to campaigns against fuel-management systems associated with gas stations and to broader targeting of Linux-based IoT and OT devices in critical infrastructure sectors. Public reporting describes IOCONTROL as a significant evolution in CyberAv3ngers tradecraft because it provides reusable, stealth-oriented access to embedded systems that can influence physical operations indirectly, even though deterministic PLC logic manipulation has not been demonstrated for IOCONTROL itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-22681 is a critical authentication bypass in Rockwell Automation's Logix controller ecosystem caused by an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Anyone who can obtain or intercept that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers. | In Phase Three (2024–2025), the group deployed IOCONTROL, a custom-built malware platform for IoT and OT devices.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Team82 obtained a sample of a custom-built IoT/OT malware called IOCONTROL used by Iran-affiliated attackers to attack Israel- and U.S.-based OT/IoT devices.
Team82, Claroty’s threat intelligence research team, obtained a sample of IOCONTROL, custom-built malware that infects Internet of Things (IoT) and operational technology (OT) systems.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware's configuration is encrypted using AES-256-CBC.
the malware was using an open-source packer solution called UPX that may have been modified specifically for this malware sample.
the malware uses AES-256-CBC decryption scheme to extract the actual configuration entry.
Self-delete : Removes its own binaries, scripts, and logs to evade detection.
Self-delete Stop the malware execution, as well as remove malware main binary, its persistence service, and related logs files.
For secure communication between compromised devices and the attackers, IOCONTROL leverages the MQTT protocol as a dedicated IoT communication channel. | After translating this hostname into IP address, the malware takes the second configuration parameter: 8883, and uses it as the port to connect to the C2. Port 8883 is usually used by the MQTTs communication protocol.
the malware does not use DNS to translate this hostname directly, instead it uses DNS over HTTPS (DoH) to translate it via CloudFlare’s API.
T1071.005 Publish/Subscribe Protocols is a sub-technique of Application Layer Protocols (T1071) in the MITRE ATT&CK framework, under the Command and Control tactic.
Examples include “(Invoke-WebRequest …).content | Invoke-Expression”, “curl … -o …”, and downloading fake Webex binary.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware kit attributed in the article to CyberAv3ngers, designed to target operational technology and IoT devices in critical infrastructure environments.
A custom-built malware platform for IoT and OT devices used by CyberAv3ngers during its capability escalation.
A Linux-based embedded OT/IoT backdoor for ARM platforms that provides persistence, encrypted configuration, MQTT-based command-and-control, device profiling, arbitrary command execution, internal scanning, output exfiltration, and self-delete capability. It has been observed targeting fuel-management systems and other OT-adjacent embedded devices.
A modular malware platform targeting Linux-based IoT and OT devices. It uses MQTT over TLS on port 8883 for command-and-control, DNS-over-HTTPS for domain resolution, stores configuration encrypted with AES-256-CBC, persists via a systemd boot script, and can execute system commands, scan ports, or delete itself on demand.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.