Summary
On 10 December 2024, Claroty Team82 published an analysis of IOCONTROL, a custom malware framework for embedded Linux IoT and OT devices. Claroty describes it as “a cyberweapon used by a nation-state to attack civilian critical infrastructure” and attributes it to CyberAv3ngers, assessed to be part of Iran’s IRGC Cyber-Electronic Command. The group behind the 2023 Unitronics PLC attacks had moved from defacing exposed devices to deploying its own malware.
IOCONTROL is vendor-agnostic. Team82 lists devices from Orpak, Gasboy, D-Link, Hikvision, Red Lion, Phoenix Contact, Teltonika, Unitronics and Baicells, covering:
- IP cameras, routers and firewalls;
- PLCs and HMIs;
- fuel management systems at petrol stations (Orpak, Gasboy), a particular focus in Israel and the United States.
For command and control it uses MQTT over port 8883. It resolves its C2 through DNS-over-HTTPS to hide the lookups from network monitoring. Its commands let the operator run arbitrary OS commands, scan an IP range on a chosen port, and self-delete (removing the binary, its persistence service and logs).
Apa maksudnya untuk Malaysia? 🇲🇾
IOCONTROL targets the “unmanaged middle” of OT: devices that sit on the edge of industrial and commercial networks and rarely get patched, logged or monitored. Petrol-station forecourts, water and building management, and industrial routers all fit that profile in Malaysia too. Given the March 2026 escalation covered in Rectifyq’s Iran conflict analysis, organisations operating equipment from the vendors above should:
- Inventory embedded devices (routers, cameras, fuel and building controllers) and remove any direct internet exposure.
- Watch for MQTT on port 8883 to unknown internet brokers and DNS-over-HTTPS from devices that should not use it. Embedded devices rarely have a legitimate reason for either.
- Change default credentials and keep firmware current. Exposed, default-credential devices were the group’s documented entry point in 2023.
Details / TTPs (ATT&CK for ICS)
| Technique | Name | Observed behavior |
|---|---|---|
| T0869 | Standard Application Layer Protocol | MQTT over TCP 8883 for command and control |
| T0846.001 | Port Scan | Operator-tasked scan of an IP range on a chosen port |
DNS-over-HTTPS C2 resolution is not modelled in ATT&CK for ICS. It corresponds to Enterprise techniques for encrypted/tunnelled DNS.
Detection guidance
- Egress-filter OT and IoT segments: deny by default, and alert on outbound MQTT (8883) and DoH endpoints.
- Alert on new outbound destinations from embedded devices; their traffic patterns are stable, so deviations are cheap to spot.
- Re-image or replace devices that show signs of compromise; persistence on embedded Linux can survive casual reboots.
IoCs
Sample hashes, C2 domains and IPs are published in the Claroty Team82 report.
References
- Claroty Team82, Inside a New OT/IoT Cyber Weapon: IOCONTROL (10 Dec 2024): https://claroty.com/team82/research/inside-a-new-ot-iot-cyber-weapon-iocontrol