The Iranian group Cyber Av3ngers has been targeting industrial machines and IoT devices, ranging from gas pumps to IP cameras. Their main tool, the IOCONTROL malware, is designed to compromise these devices and cause critical disruptions.
Researchers from Team82, part of Claroty, analyzed this malware, highlighting its ability to exploit vulnerabilities in devices from various manufacturers, such as D-Link and Hikvision. Cyber Av3ngers have already breached 200 gas stations in Israel and the U.S., with the potential to sabotage services and steal sensitive data like credit card information.
IOCONTROL is capable of disabling devices, disrupting operations, and even spreading across networks, posing a serious threat to critical infrastructure. The malware uses encrypted protocols and advanced mechanisms to remain hidden and persistent.
Cyber Av3ngers are focused on disrupting essential services in Israel and the U.S., driven by geopolitical tensions. Authorities, including CISA, recommend robust cybersecurity measures such as regular assessments, updates, and network segmentation to defend against such attacks.
Recent Activities of Cyber Av3ngers
The Cyber Av3ngers group, linked to Iran, has been conducting a series of cyberattacks targeting industrial and Internet of Things (IoT) devices in Israel and the United States. Their primary tool, the IOCONTROL malware, has already compromised hundreds of systems, including 200 gas pumps. This malware was built from scratch, showcasing advanced sophistication.
Affected Devices and Manufacturers
Cyber Av3ngers target a variety of industrial devices, including:
- Gas pumps (Gasboy and Orpak).
- Routers and firewalls from brands like D-Link and Teltonika.
- IP cameras from Hikvision.
- Programmable logic controllers (PLC) and human-machine interfaces (HMI) produced by Phoenix Contact, Red Lion, and Unitronics.
The malware exploits vulnerabilities in these devices to remotely control them, disrupt services, or cause permanent damage.
How IOCONTROL Works
- Initial Attack Phase: Hackers look for vulnerabilities in industrial devices using automated analysis tools. Once identified, these flaws are exploited to install the malware.
- Persistence: IOCONTROL installs a backdoor in affected devices, ensuring it remains active even after reboots.
- Propagation: The malware uses the MQTT protocol to communicate with attacker-controlled command-and-control (C2) servers. To conceal this communication, it employs DNS over HTTPS (DoH), making malicious traffic harder to detect.
- Capabilities: IOCONTROL can:
- Steal data, such as credit card information.
- Disrupt the operation of devices.
- Overload systems with excessive commands.
- Disable critical functions of industrial devices.
- Spread to other connected systems.

Reconstruction of IOCONTROL MQTT connection message (C2 servers) by Team82. (Team82
Geopolitical Context
The attacks focus on critical infrastructure in Israel and the United States, such as water, energy, and gas stations. These actions are motivated by political tensions between Iran and these countries. One example was the Thanksgiving 2023 attack, where Cyber Av3ngers disrupted the water supply in a Pennsylvania town to demonstrate the vulnerability of water systems.
Authorities’ Response
The U.S. government has imposed sanctions on six Iranian officials linked to the group and offered a $10 million reward for information leading to the identification of those responsible. Additionally, organizations like the Cybersecurity and Infrastructure Security Agency (CISA) have released guidelines to protect critical infrastructure.
Recommendations for Protection
- Vulnerability Assessments: Conduct regular analyses to identify potential flaws in industrial systems.
- Patching: Keep software and firmware updated.
- Network Segmentation: Separate critical systems from the rest of the network to limit the impact of an attack.
- Monitoring: Deploy tools to detect anomalous traffic and identify suspicious activities.
- Training: Educate staff about cyber threats and the importance of cybersecurity.
Conclusion
The Cyber Av3ngers pose a significant threat to critical infrastructure. Their ability to cause widespread disruptions and steal sensitive information makes them a growing risk in modern cyber warfare. Collaboration between governments, businesses, and cybersecurity experts will be key to mitigating these risks and safeguarding essential services for the public.
By: Nestor Castillo, ForAllTechNews DIrector
