IOCONTROL is a custom Linux-based malware platform and backdoor associated with the Iran-linked CyberAv3ngers persona, which has been assessed as affiliated with the Islamic Revolutionary Guard Corps Cyber-Electronic Command. It is designed for operational technology and Internet of Things environments and has been used against civilian critical infrastructure, including fuel-management deployments and other embedded industrial or OT-adjacent systems.
The malware targets Linux-based embedded devices, with reporting describing use against routers, firewalls, IP cameras, gateways, HMIs, PLC-adjacent devices, and fuel-management systems. Analyses describe IOCONTROL as modular and configurable, with variants compiled for embedded Linux architectures including ARM. It has been characterized as a purpose-built access platform for OT and IoT operations rather than a purely demonstrative or propaganda artifact.
Documented IOCONTROL functionality includes persistence through Linux startup mechanisms, encrypted configuration storage, device profiling, arbitrary command execution, internal network scanning, output exfiltration, and self-deletion. Command-and-control communications use MQTT, including MQTT over TLS, and the malware has also been reported to use DNS-over-HTTPS to support stealthier infrastructure resolution. Structured tasking and beaconing enable operators to manage infected devices and collect host information while blending with legitimate IoT-style traffic patterns.
IOCONTROL represents an evolution in CyberAv3ngers tradecraft from earlier disruptive activity involving exposed PLCs and default credentials toward repeatable implant-based access in OT and IoT environments. It has been linked to campaigns affecting Israeli and U.S.-based infrastructure and to compromises involving fuel-sector technology from multiple vendors. Available reporting supports its role as an operational access and control tool for embedded Linux systems in critical infrastructure environments; although it increases disruption risk substantially, current public reporting does not demonstrate deterministic PLC logic manipulation by IOCONTROL itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-22681 is a critical authentication bypass in Rockwell Automation's Logix controller ecosystem caused by an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Anyone who can obtain or intercept that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers. | In Phase Three (2024–2025), the group deployed IOCONTROL, a custom-built malware platform for IoT and OT devices.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Between 2024 and 2025, the crew developed the IOCONTROL malware kit, built for attacks on OT and Internet of Things (IoT) devices.
Team82, Claroty’s threat intelligence research team, obtained a sample of IOCONTROL, custom-built malware that infects Internet of Things (IoT) and operational technology (OT) systems.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Key technical characteristics include ... capabilities including OS command execution, port scanning, and self-deletion.
It used MQTT for C2 and was configured with victim-specific identifiers. | IOCONTROL introduces durable persistence, encrypted configuration (AES-class schemes), MQTT-based command-and-control... IOCONTROL’s MQTT C2 model... Claroty reports the sample... used MQTT for C2
Key technical characteristics include MQTT over TLS for C2 communications on port 8883, DNS-over-HTTPS to evade network monitoring when resolving C2 domains.
T1071.005 Publish/Subscribe Protocols is a sub-technique of Application Layer Protocols (T1071) in the MITRE ATT&CK framework, under the Command and Control tactic.
Examples include “(Invoke-WebRequest …).content | Invoke-Expression”, “curl … -o …”, and downloading fake Webex binary.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware kit attributed in the article to CyberAv3ngers, designed to target operational technology and IoT devices in critical infrastructure environments.
A custom-built malware platform for IoT and OT devices used by CyberAv3ngers during its capability escalation.
A Linux-based embedded OT/IoT backdoor for ARM platforms that provides persistence, encrypted configuration, MQTT-based command-and-control, device profiling, arbitrary command execution, internal scanning, output exfiltration, and self-delete capability. It has been observed targeting fuel-management systems and other OT-adjacent embedded devices.
A modular malware platform targeting Linux-based IoT and OT devices. It uses MQTT over TLS on port 8883 for command-and-control, DNS-over-HTTPS for domain resolution, stores configuration encrypted with AES-256-CBC, persists via a systemd boot script, and can execute system commands, scan ports, or delete itself on demand.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.