IOCONTROL is a custom Linux malware platform used in operations attributed to the Iran-linked CyberAv3ngers cluster, which is widely assessed as affiliated with the Islamic Revolutionary Guard Corps Cyber-Electronic Command. It is purpose-built for IoT, OT, and SCADA-adjacent environments and has been observed targeting embedded Linux devices associated with civilian critical infrastructure, including fuel management systems, routers, programmable logic controllers, human-machine interfaces, firewalls, IP cameras, and other industrial or edge devices. Reported victim geography includes Israel and the United States, with activity tied particularly to fuel and water-related infrastructure and broader OT environments.
Functionally, IOCONTROL is best characterized as a modular backdoor for embedded Linux systems. It maintains persistence through boot-time initialization scripts, stores encrypted configuration data, and uses DNS over HTTPS together with MQTT-based command and control to blend with legitimate IoT-style traffic and reduce visibility to conventional monitoring. The malware profiles infected devices by collecting host and system information, supports arbitrary operating-system command execution, can verify implant presence, scan internal networks and ports for additional reachable systems, return command output to operators, and remove itself to hinder forensic recovery. These features make it suitable for sustained post-compromise access, reconnaissance inside OT-adjacent networks, and operational disruption when deployed on devices that mediate physical processes.
IOCONTROL has been described as an evolution from earlier CyberAv3ngers activity that relied heavily on exposed industrial devices and weak or default credentials. Its deployment demonstrates a shift from opportunistic defacement and direct controller abuse toward reusable implant-based access in embedded OT and IoT environments. Public reporting has linked IOCONTROL to campaigns affecting fuel management ecosystems, including systems whose compromise could disrupt fuel distribution and potentially expose payment-related data. Available evidence supports IOCONTROL as a high-confidence nation-state OT/IoT access tool rather than a purely demonstrative or influence-oriented artifact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-22681 is a critical authentication bypass in Rockwell Automation's Logix controller ecosystem caused by an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Anyone who can obtain or intercept that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers. | In Phase Three (2024–2025), the group deployed IOCONTROL, a custom-built malware platform for IoT and OT devices.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In December 2024, researchers tied the group to IOCONTROL (also called OrpaCrab), a malware family built specifically for OT and IoT devices, and Nozomi Networks Labs later observed the group reusing infrastructure from that campaign.
Team82, Claroty’s threat intelligence research team, obtained a sample of IOCONTROL, custom-built malware that infects Internet of Things (IoT) and operational technology (OT) systems.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware's configuration is encrypted using AES-256-CBC.
the malware was using an open-source packer solution called UPX that may have been modified specifically for this malware sample.
the malware uses AES-256-CBC decryption scheme to extract the actual configuration entry.
Self-delete : Removes its own binaries, scripts, and logs to evade detection.
Self-delete Stop the malware execution, as well as remove malware main binary, its persistence service, and related logs files.
For secure communication between compromised devices and the attackers, IOCONTROL leverages the MQTT protocol as a dedicated IoT communication channel. | After translating this hostname into IP address, the malware takes the second configuration parameter: 8883, and uses it as the port to connect to the C2. Port 8883 is usually used by the MQTTs communication protocol.
the malware does not use DNS to translate this hostname directly, instead it uses DNS over HTTPS (DoH) to translate it via CloudFlare’s API.
T1071.005 Publish/Subscribe Protocols is a sub-technique of Application Layer Protocols (T1071) in the MITRE ATT&CK framework, under the Command and Control tactic.
Examples include “(Invoke-WebRequest …).content | Invoke-Expression”, “curl … -o …”, and downloading fake Webex binary.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family built specifically for OT and IoT devices, associated in the content with IRGC-affiliated CyberAv3ngers activity.
A malware kit attributed in the article to CyberAv3ngers, designed to target operational technology and IoT devices in critical infrastructure environments.
A custom-built malware platform for IoT and OT devices used by CyberAv3ngers during its capability escalation.
A Linux-based embedded OT/IoT backdoor for ARM platforms that provides persistence, encrypted configuration, MQTT-based command-and-control, device profiling, arbitrary command execution, internal scanning, output exfiltration, and self-delete capability. It has been observed targeting fuel-management systems and other OT-adjacent embedded devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.