HomeSecurityIOCONTROL malware targets critical infrastructure in the US and Israel

IOCONTROL malware targets critical infrastructure in the US and Israel

Iranian hackers are using a new malware, IOCONTROL, to compromise Internet of Things (IoT) devices and OT/SCADA systemsused in critical infrastructure in Israel and the United States.

IOCONTROL malware critical infrastructure

Targeted devices include routers, programmable logic controllers (PLCs), human-machine interfaces (HMIs), IP cameras, firewalls , and fuel management systems.

The modular nature of the IOCONTROL malware allows it to compromise a wide range of devices from various manufacturers, including D-Link, Hikvision, Baicells, Red Lion, Orpak, Phoenix Contact, Teltonika, and Unitronics.

Claroty's Team82 researchers , who discovered and tested a sample of IOCONTROL, report that it is a tool used by Iranian state hackers that can cause significant disruptions to critical infrastructure.

Given the ongoing geopolitical conflicts, IOCONTROL is being used to target Israel and US systems, such as the Orpak and Gasboy.

The tool is reportedly linked to Iranian hackers CyberAv3ngers, who have attacked industrial systems in the past.

IOCONTROL malware targets critical infrastructure

Claroty extracted samples of the malware from a Gasboy control system, but researchers don't know exactly how the hackers infected it with IOCONTROL.

Within these devices, IOCONTROL could control pumps, payment terminals, and other peripheral systems, potentially causing downtime or data theft.

The attackers claimed, on Telegram, that they had compromised 200 gas stations in Israel and the US, which aligns with Claroty's findings.

These attacks occurred in late 2023, but researchers report that new campaigns appeared in mid-2024.

As of December 10, 2024, the UPX-packed malware binary is not detected by any of VirusTotal's 66 antivirus engines.

Characteristics of IOCONTROL malware

The malware, which is stored in the '/usr/bin/' directory under the name 'iocontrol', uses a modular configuration to adapt to different vendors and device types.

Researchers observed that it uses a persistence script ('S93InitSystemd.sh') to execute the malware process ('iocontrol') at system startup. This means that rebooting the device does not disable it.

It also uses the MQTT protocol over port 8883 to communicate with the command and control (C2) server, which is a standard channel and protocol for IoT devices. Unique device IDs are embedded in the MQTT credentials for better control.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What commands does IOCONTROL malware support:

  • Send “hello”: Reports detailed system information to the C2.
  • Check exec: Confirms that the malware binary is properly installed and can be executed.
  • Execute command: Executes arbitrary operating system via system calls.
  • Self-delete: Removes its own binaries, scripts, and logs to avoid detection.
  • Port scan: Scans specified IP ranges and ports to identify other potential targets.

The full indicators of compromise (IoC) are listed at the bottom of Claroty's report

Since IOCONTROL malware targets critical infrastructure, taking protective measures is essential.

IOCONTROL malware targets critical infrastructure in the US and Israel

Malware protection

Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.

Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks, which attackers often use to install malware.

It's also important to keep your operating system and applications up to date. These updates often include security fixes that can protect your computer from the latest threats.

Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS