Threats Feed|CyberAv3ngers|Last Updated 28/01/2026|AuthorCertfa Radar|Publish Date10/12/2024

CyberAv3ngers’ Malware Hits IoT/OT Systems in Fuel and Energy Sectors

  • Actor Motivations: Sabotage
  • Attack Vectors: Vulnerability Exploitation,Backdoor,Malware
  • Attack Complexity: High
  • Threat Risk: High Impact/Low Probability

Threat Overview

Team82's research details the IOCONTROL malware, a custom-built cyberweapon used by Iran-linked attackers, specifically the CyberAv3ngers group. The malware targets a range of industrial control systems (ICS) and Internet of Things (IoT) devices, notably impacting fuel management systems in Israel and the US. IOCONTROL's functionality includes communication via the MQTT protocol and features such as arbitrary code execution and self-deletion. The analysis reveals the malware's infrastructure, including its command-and-control server and the methods used to evade detection. The report concludes that IOCONTROL represents a significant threat to critical infrastructure, highlighting the ongoing geopolitical conflict.

Detected Targets

TypeDescriptionConfidence
SectorManufacturing
High
SectorEnergy
High
SectorOil and Gas
High
RegionIsrael
Verified
RegionUnited States
Verified

Extracted IOCs

  • ocferda[.]com
  • tylarion867mino[.]com
  • uuokhhfsdlk.tylarion867mino[.]com
  • 1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498
  • 159[.]100.6.69
download

Tip: 5 related IOCs (1 IP, 3 domain, 0 URL, 0 email, 1 file hash) to this threat have been found.

About Affiliation
CyberAv3ngers
CyberAv3ngers is an IRGC-linked Iranian hacktivist group specializing in attacks against industrial control systems (ICS) and operational technology (OT), particularly internet-exposed programmable logic controllers (PLCs). The group gained international attention in late 2023 after compromising Unitronics PLCs at water and wastewater utilities across the United States following the Hamas-Israel conflict. US authorities — including CISA, FBI, EPA, and NSA — attributed these attacks to the IRGC, and the US Treasury sanctioned six IRGC Cyber Command officers linked to the group in February 2024.
View CyberAv3ngers's Insights