Claroty’s Team82 reported that IOCONTROL, a custom malware attributed to Iran-affiliated actors and linked to CyberAv3ngers, was used against civilian critical infrastructure in Israel and the United States. The malware was recovered from a Gasboy fuel control system payment terminal and is designed to compromise a broad range of Linux-based IoT and OT assets, including Orpak and Gasboy fuel management systems, routers, PLCs, HMIs, firewalls, and IP cameras. Researchers said the activity aligns with prior CyberAv3ngers operations against Unitronics devices at water facilities and with the group’s claims of compromising hundreds of gas stations.
The malware was described as a modular cyberweapon built for stealth and persistence. Team82 said IOCONTROL uses modified UPX-style packing, an AES-256-CBC encrypted configuration derived from a hardcoded GUID, DNS over HTTPS via Cloudflare for command-and-control resolution, and secure MQTT over port 8883 for communications. It establishes persistence through an rc3.d boot script, sends a JSON-based "hello" beacon to identify infected devices, and supports arbitrary command execution, self-deletion, executable verification, and port scanning. Researchers also noted that, as of December 10, 2024, the analyzed IOCONTROL sample reportedly evaded detection by all 66 antivirus engines on VirusTotal.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
As of December 10, 2024, BleepingComputer reported that none of 66 antivirus engines on VirusTotal detected the UPX-packed IOCONTROL binary. This indicated the sample was still evading mainstream AV detection at that time.
Researchers reported that IOCONTROL activity resumed in mid-2024, with Claroty describing a relaunch in July-August 2024. The renewed campaign continued targeting IoT and OT devices associated with critical infrastructure.
Claroty said the IOCONTROL campaign against Orpak devices spanned from mid-October 2023 to late January 2024. The activity affected fuel management environments in Israel and the United States.
The IOCONTROL command-and-control infrastructure included the domain tylarion867mino.com, which Claroty said was registered on November 23, 2023. The malware later used a hostname under this domain for C2 communications.
Claroty reported that an IOCONTROL campaign targeting Israel-made Orpak Systems and U.S.-made Gasboy fuel management systems began in mid-October 2023 in Israel and the United States. One attack wave compromised several hundred devices tied to these vendors.
Claroty Team82 published analysis of IOCONTROL, describing it as a custom IoT/OT malware used by Iran-affiliated attackers and linking the activity to CyberAv3ngers. The report said the malware targeted Israel- and U.S.-based critical infrastructure devices including routers, PLCs, HMIs, firewalls, IP cameras, and fuel management systems.
CyberAv3ngers claimed on Telegram that it had attacked 200 gas stations in Israel and the United States targeting Orpak systems, and shared screenshots and leaked target data. Claroty said these claims aligned with its findings on the IOCONTROL activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.