216.73.216.226

Inside a New OT/IoT Cyberweapon: IOCONTROL

· Published 11/12/2024 19:19 · Modified 11/12/2024 19:35

Export JSON

Essential information

Published
11/12/2024 19:19
Modified
11/12/2024 19:35
Tags
2024-12-11 iocontrol iot mqtt scada
Related entities
4 observables, 1 intrusion sets (apt), 20 techniques (mitre), 1 malware, 4 others

Description

Team82 analyzed a sample of , a custom-built /OT malware used by Iran-affiliated attackers to target Israel and U.S.-based devices. The malware affects various and /OT devices, including IP cameras, routers, PLCs, HMIs, and firewalls from multiple vendors. is believed to be part of a global cyber operation against western and OT devices, likely used as a cyberweapon by a nation-state to attack civilian critical infrastructure. The malware uses the protocol for C2 communication and employs stealth techniques like DNS over HTTPS. It has capabilities for arbitrary code execution, self-deletion, port scanning, and persistence through a daemon installation.

External references