IOCONTROL, also known as OrpaCrab, is a custom Linux-based backdoor targeting embedded Internet of Things (IoT), operational technology (OT), and SCADA environments. It is attributed to CyberAv3ngers, an Iranian threat group linked to the Islamic Revolutionary Guard Corps Cyber-Electronic Command. IOCONTROL has been deployed against civilian critical infrastructure in Israel and the United States, notably Orpak and Gasboy fuel-management systems. Targeted device categories include routers, firewalls, IP cameras, programmable logic controllers, and human-machine interfaces. Its modular configuration supports adaptation to different vendors and device architectures; an analyzed sample targeted 32-bit big-endian ARM systems.
IOCONTROL establishes persistence through Linux startup scripts and communicates with its command infrastructure using MQTT over TLS. Device-specific identifiers enable individual tasking, while structured messages report host information and command output. Supported functions include arbitrary operating-system command execution, installation and executable checks, port scanning across address ranges, and self-deletion. These capabilities provide persistent remote access, reconnaissance, and data exfiltration from compromised devices.
Defense-evasion mechanisms include modified UPX-style packing, AES-256-CBC-encrypted configuration entries decrypted at runtime, DNS-over-HTTPS resolution, and removal of malware artifacts and logs. IOCONTROL was recovered from a Gasboy fuel-system payment terminal, where compromise creates opportunities to interfere with fuel services and connected peripherals. Its precise initial infection vector has not been established, and its demonstrated capabilities do not establish deterministic manipulation of PLC control logic.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-22681 is a critical authentication bypass in Rockwell Automation's Logix controller ecosystem caused by an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Anyone who can obtain or intercept that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers. | In Phase Three (2024–2025), the group deployed IOCONTROL, a custom-built malware platform for IoT and OT devices.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group’s past activity, most notably through the development of a custom malware framework known as IOCONTROL, focuses on operational technology and connected IoT devices and systems.
Team82, Claroty’s threat intelligence research team, obtained a sample of IOCONTROL, custom-built malware that infects Internet of Things (IoT) and operational technology (OT) systems.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware's configuration is encrypted using AES-256-CBC.
the malware was using an open-source packer solution called UPX that may have been modified specifically for this malware sample.
the malware uses AES-256-CBC decryption scheme to extract the actual configuration entry.
Self-delete : Removes its own binaries, scripts, and logs to evade detection.
Self-delete Stop the malware execution, as well as remove malware main binary, its persistence service, and related logs files.
For secure communication between compromised devices and the attackers, IOCONTROL leverages the MQTT protocol as a dedicated IoT communication channel. | After translating this hostname into IP address, the malware takes the second configuration parameter: 8883, and uses it as the port to connect to the C2. Port 8883 is usually used by the MQTTs communication protocol.
the malware does not use DNS to translate this hostname directly, instead it uses DNS over HTTPS (DoH) to translate it via CloudFlare’s API.
T1071.005 Publish/Subscribe Protocols is a sub-technique of Application Layer Protocols (T1071) in the MITRE ATT&CK framework, under the Command and Control tactic.
Examples include “(Invoke-WebRequest …).content | Invoke-Expression”, “curl … -o …”, and downloading fake Webex binary.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware used against industrial-control and IoT devices.
An IoT malware family mentioned solely as one of three prior examples of malware using MQTT communications.
Operational-technology malware targeting IoT and SCADA environments.
A malware family built specifically for OT and IoT devices, associated in the content with IRGC-affiliated CyberAv3ngers activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.