IOCONTROL is a custom Linux-based backdoor and malware platform designed for IoT, OT, and SCADA environments. The content attributes it to CyberAv3ngers, a persona assessed as affiliated with Iran’s IRGC Cyber-Electronic Command, and describes it as a nation-state cyberweapon used against civilian critical infrastructure. Claroty Team82 analyzed IOCONTROL and reported that the sampled malware was compiled for ARM 32-bit big-endian Linux, used a modified UPX-like packing method, and stored configuration data encrypted with AES-256-CBC.
The malware is described as targeting Linux-based embedded and OT-adjacent devices including routers, firewalls, IP cameras, PLCs, HMIs, gateways, and fuel management systems. Named affected or targeted vendors in the content include D-Link, Hikvision, Baicells, Red Lion, Orpak, Phoenix Contact, Teltonika, Unitronics, and Gasboy. The content states that IOCONTROL was observed in real environments including Orpak and Gasboy fuel-management deployments, with campaigns compromising several hundred fuel management systems in Israel and the United States. It is also described as targeting Israeli- and U.S.-based IoT and ICS devices and U.S. critical infrastructure more broadly.
Reported capabilities include persistence via Linux init or systemd boot scripts, encrypted configuration handling, MQTT-based command-and-control, DNS-over-HTTPS for domain resolution, device profiling, arbitrary OS command execution, internal network scanning, output exfiltration, and self-delete functionality. The content states that IOCONTROL uses MQTT over TLS, commonly on port 8883, and also references ports 1883 and 15672. MQTT tasking paths mentioned include {GUID}/hello, {GUID}/push, and {GUID}/output. Behavioral indicators described in the content include MQTT beaconing from OT/IoT devices, outbound DNS-over-HTTPS, internal scanning from embedded devices, and command execution via broker-delivered tasking. The malware is described as collecting host information such as kernel version, hostname, user identity, and timezone, and using structured JSON beacon and command messages.
The content identifies IOCONTROL-related artifacts including file paths /usr/bin/iocontrol, /tmp/iocontrol, /var/run/iocontrol.pid, and /etc/rc3.d/S93InitSystemd.sh. Reported network infrastructure includes domains uuokhhfsdlk.tylarion867mino[.]com and ocferda[.]com; IPs 159[.]100[.]6[.]69, 104[.]21[.]62[.]225, 172[.]67[.]139[.]215, and 3[.]217[.]232[.]142; and a primary MQTT C2 address of 159[.]100[.]6[.]69. Hashes associated with IOCONTROL in the content include SHA-256 1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498 and bc160db9bdf6758cafaa1940b8cbe1608fe3f236743d312a08568fa0fb1250ab, SHA-1 366e435a1ea0f597deb6ebe7c0c5acdb6e8b33eb, and MD5 c92e2655d115368f92e7b7de5803b7bc.
The content assesses IOCONTROL as a meaningful evolution from CyberAv3ngers’ earlier PLC and HMI defacement activity into repeatable implant-based access against civilian critical infrastructure, especially fuel and other OT-adjacent environments. It explicitly notes that IOCONTROL provides persistent access and command execution on OT-connected devices, increasing disruption risk, but that the reported sample does not yet demonstrate deterministic PLC logic manipulation. The malware was also previously tracked under the names OrpaCrab, OrpraCab, and QueueCat before being identified as IOCONTROL.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The inflection point is IOCONTROL, a custom Linux/ARM OT-IoT backdoor attributed to CyberAv3ngers, a persona assessed as affiliated with the IRGC Cyber-Electronic Command.
Team82, Claroty’s threat intelligence research team, obtained a sample of IOCONTROL, custom-built malware that infects Internet of Things (IoT) and operational technology (OT) systems.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Key technical characteristics include ... capabilities including OS command execution, port scanning, and self-deletion.
It used MQTT for C2 and was configured with victim-specific identifiers. | IOCONTROL introduces durable persistence, encrypted configuration (AES-class schemes), MQTT-based command-and-control... IOCONTROL’s MQTT C2 model... Claroty reports the sample... used MQTT for C2
Key technical characteristics include MQTT over TLS for C2 communications on port 8883, DNS-over-HTTPS to evade network monitoring when resolving C2 domains.
T1071.005 Publish/Subscribe Protocols is a sub-technique of Application Layer Protocols (T1071) in the MITRE ATT&CK framework, under the Command and Control tactic.
Examples include “(Invoke-WebRequest …).content | Invoke-Expression”, “curl … -o …”, and downloading fake Webex binary.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux-based embedded OT/IoT backdoor for ARM platforms that provides persistence, encrypted configuration, MQTT-based command-and-control, device profiling, arbitrary command execution, internal scanning, output exfiltration, and self-delete capability. It has been observed targeting fuel-management systems and other OT-adjacent embedded devices.
A modular malware platform targeting Linux-based IoT and OT devices. It uses MQTT over TLS on port 8883 for command-and-control, DNS-over-HTTPS for domain resolution, stores configuration encrypted with AES-256-CBC, persists via a systemd boot script, and can execute system commands, scan ports, or delete itself on demand.
A custom-built modular Linux malware platform for IoT/OT devices that targets routers, PLCs, HMIs, IP cameras, firewalls, and fuel management systems. It uses MQTT over TLS for C2, DNS-over-HTTPS for resolution evasion, AES-256-CBC encrypted configuration data, persistence via a systemd boot script, and supports OS command execution, port scanning, and self-deletion.
A nation-state malware platform used against civilian critical infrastructure. It uses MQTT for command-and-control, routes DNS lookups over HTTPS to evade monitoring, and targets PLCs, fuel management systems, IP cameras, routers, firewalls, and other industrial devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.