Iranian hackers are using a new malware, IOCONTROL, to compromise Internet of Things (IoT) devices and OT/SCADA systemsused in critical infrastructure in Israel and the United States.

Targeted devices include routers, programmable logic controllers (PLCs), human-machine interfaces (HMIs), IP cameras, firewalls , and fuel management systems.
The modular nature of the IOCONTROL malware allows it to compromise a wide range of devices from various manufacturers, including D-Link, Hikvision, Baicells, Red Lion, Orpak, Phoenix Contact, Teltonika, and Unitronics.
Claroty's Team82 researchers , who discovered and tested a sample of IOCONTROL, report that it is a tool used by Iranian state hackers that can cause significant disruptions to critical infrastructure.
Given the ongoing geopolitical conflicts, IOCONTROL is being used to target Israel and US systems, such as the Orpak and Gasboy.
The tool is reportedly linked to Iranian hackers CyberAv3ngers, who have attacked industrial systems in the past.
IOCONTROL malware targets critical infrastructure
Claroty extracted samples of the malware from a Gasboy control system, but researchers don't know exactly how the hackers infected it with IOCONTROL.
Within these devices, IOCONTROL could control pumps, payment terminals, and other peripheral systems, potentially causing downtime or data theft.
The attackers claimed, on Telegram, that they had compromised 200 gas stations in Israel and the US, which aligns with Claroty's findings.
These attacks occurred in late 2023, but researchers report that new campaigns appeared in mid-2024.
As of December 10, 2024, the UPX-packed malware binary is not detected by any of VirusTotal's 66 antivirus engines.
Characteristics of IOCONTROL malware
The malware, which is stored in the '/usr/bin/' directory under the name 'iocontrol', uses a modular configuration to adapt to different vendors and device types.
Researchers observed that it uses a persistence script ('S93InitSystemd.sh') to execute the malware process ('iocontrol') at system startup. This means that rebooting the device does not disable it.
It also uses the MQTT protocol over port 8883 to communicate with the command and control (C2) server, which is a standard channel and protocol for IoT devices. Unique device IDs are embedded in the MQTT credentials for better control.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What commands does IOCONTROL malware support:
- Send “hello”: Reports detailed system information to the C2.
- Check exec: Confirms that the malware binary is properly installed and can be executed.
- Execute command: Executes arbitrary operating system via system calls.
- Self-delete: Removes its own binaries, scripts, and logs to avoid detection.
- Port scan: Scans specified IP ranges and ports to identify other potential targets.
The full indicators of compromise (IoC) are listed at the bottom of Claroty's report
Since IOCONTROL malware targets critical infrastructure, taking protective measures is essential.

Malware protection
Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.
Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks, which attackers often use to install malware.
It's also important to keep your operating system and applications up to date. These updates often include security fixes that can protect your computer from the latest threats.
Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.
Source: www.bleepingcomputer.com
