{"id":2848,"date":"2025-03-26T10:04:06","date_gmt":"2025-03-26T10:04:06","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/26\/new-iocontrol-malware-attacking-critical-infrastructure-to-gain-remote-access-and-control\/"},"modified":"2025-03-26T10:04:06","modified_gmt":"2025-03-26T10:04:06","slug":"new-iocontrol-malware-attacking-critical-infrastructure-to-gain-remote-access-and-control","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/26\/new-iocontrol-malware-attacking-critical-infrastructure-to-gain-remote-access-and-control\/","title":{"rendered":"New IOCONTROL Malware Attacking Critical Infrastructure to Gain Remote Access and Control"},"content":{"rendered":"<p>    New IOCONTROL Malware Attacking Critical Infrastructure to Gain Remote Access and Control<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A newly identified malware strain dubbed \u201cIOCONTROL\u201d has emerged as a critical threat to operational technology (OT) and Internet of Things (IoT) systems, particularly targeting fuel-management infrastructure in the United States and Israel.<\/p>\n<p>First observed in December 2024, this Linux-based malware has been linked to the pro-Iranian hacktivist group Cyber Av3ngers, which has historically pursued anti-Israeli cyber campaigns.<\/p>\n<p>Initial attacks leveraged compromised credentials\u2014part of a broader 33% year-over-year surge in credential theft\u2014to infiltrate critical systems, enabling threat actors to establish persistent remote access, manipulate industrial processes, and exfiltrate sensitive operational data.<\/p>\n<p>Flashpoint analysts <a href=\"https:\/\/flashpoint.io\/blog\/iocontrol-malware\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> IOCONTROL\u2019s modular architecture, which combines UPX-packed binaries, encrypted command-and-control (C2) communications, and surveillance capabilities tailored for resource-constrained IoT environments.<\/p>\n<p>The malware primarily exploits vulnerabilities in internet-exposed industrial control systems (ICS), using the MQTT protocol\u2014a lightweight messaging standard common in <a href=\"https:\/\/cybersecuritynews.com\/iot-device-remotely\/\" target=\"_blank\" rel=\"noreferrer noopener\">IoT<\/a> ecosystems\u2014to bypass traditional network monitoring tools.<\/p>\n<p>Its deployment in attacks against fuel distribution networks underscores escalating risks to critical infrastructure amid heightened geopolitical tensions in the Middle East.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Technical Overview and Persistence Mechanisms<\/strong><\/h2>\n<p>IOCONTROL employs sophisticated evasion tactics, starting with a modified UPX packer that alters binary magic values to hinder static analysis.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqVUEG8GruI1BnmsWetSZqgwMC6xJ0bQDRQP9enZe24WuXooYqowT43P8gPixYQGeZmxUygnOv2Tj-8UWQOLNow0jRJVyHWzPWYb7Y6a6nNY11caIXUFhzjzTi4jRgznBPk0jHx9YQKP6XwkJ-A68v-CvYFg_WXKIgRFmsTc2PqrMaRZezxWibqnGYPxY\/s16000\/Modified%2520UPX%2520magic%2520value%2520%28Source%2520-%2520FlashPoint%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Modified UPX magic value (Source \u2013 FlashPoint)<\/figcaption><\/figure>\n<\/div>\n<p>While standard UPX utilities fail to unpack the malware due to these alterations, Flashpoint researchers demonstrated that restoring the magic bytes (<code>00 00 00 00 00 00 00 02 00 34 00 20 00 02 00 34<\/code>) enables successful decompression.<\/p>\n<p>Once executed, the malware unpacks itself in memory and establishes persistence through a multi-stage process:-<\/p>\n<ol class=\"wp-block-list\">\n<li>\n<strong>Directory Creation<\/strong>: IOCONTROL creates two directories\u2014<code>\/tmp\/iocontrol\/<\/code> and <code>\/etc\/rc3.d<\/code>\u2014with full read, write, and execute permissions. These serve as operational hubs for staging payloads and maintaining <a href=\"https:\/\/cybersecuritynews.com\/malware-com-hijacking-persistence\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> across reboots.<\/li>\n<li>\n<strong>Startup Script Injection<\/strong>: A bash script is written to <code>\/etc\/rc3.d\/S99iocontrol<\/code>, ensuring execution at system startup. The script includes watchdog functionality to restart the malware if terminated:<\/li>\n<\/ol>\n<pre class=\"wp-block-code\"><code>#!\/bin\/sh\n\/usr\/bin\/iocontrol &gt;\/dev\/null 2&gt;&amp;1 &amp;\nwhile true; do\n  if ! pgrep -x \"iocontrol\" &gt;\/dev\/null; then\n    \/usr\/bin\/iocontrol &gt;\/dev\/null 2&gt;&amp;1 &amp;\n  fi\n  sleep 60\ndone<\/code><\/pre>\n<p>This mechanism ensures continuous operation even if security tools interrupt initial execution.<\/p>\n<ol start=\"3\" class=\"wp-block-list\">\n<li>\n<strong>C2 Communication<\/strong>: The malware resolves its C2 server\u2019s IP via a DNS query to CloudFlare, extracting the <code>Answer[data]<\/code> field from the response. It then establishes an MQTT connection to the broker, transmitting beacon packets containing system metadata (kernel version, hostname, time zone) encrypted using AES-256-CBC. The encryption key derives from environment variables <code>0_0<\/code> and <code>0_1<\/code>, set during execution, which store hashed GUID values split into key and initialization vector (IV) components.<\/li>\n<\/ol>\n<p>IOCONTROL\u2019s blend of IoT-focused protocols and credential-based initial access vectors presents unique challenges for defenders.<\/p>\n<p>Flashpoint\u2019s investigation revealed attempts by the malware\u2019s developer to sell it on underground forums like BreachForums, signaling potential proliferation across threat actor groups.<\/p>\n<p>Organizations managing OT environments must prioritize firmware patching, <a href=\"https:\/\/cybersecuritynews.com\/10-effective-ways-to-improve-network-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">network segmentation<\/a>, and anomaly detection for MQTT traffic to mitigate risks posed by this evolving threat.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=enrichment&amp;utm_content=plans&amp;utm_term=180325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-iocontrol-malware-attacking-critical-infrastructure\/\">New IOCONTROL Malware Attacking Critical Infrastructure to Gain Remote Access and Control<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-iocontrol-malware-attacking-critical-infrastructure\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New IOCONTROL Malware Attacking Critical Infrastructure to Gain Remote Access and Control A newly identified malware strain dubbed \u201cIOCONTROL\u201d has emerged as a critical threat to operational technology (OT) and Internet of Things (IoT) systems, particularly targeting fuel-management infrastructure in the United States and Israel. First observed in December 2024, this Linux-based malware has been [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,258,649],"tags":[130],"class_list":["post-2848","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-malware","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2848"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2848"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2848\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}