U.S. Offers $10 Million Bounty for Iranian Operator of IOControl Malware
Articles by the same author:
1
2
3
4
The U.S. Department of State announced on June 16, 2025, a $10 million reward (€8.7 million) for information leading to the capture of an Iranian cybercriminal accused of conducting malicious cyber operations on behalf of the Islamic Revolutionary Guard Corps’ Cyber-Electronic Command (IRGC-CEC).
Known by the aliases “Mr. Soul” and “Mr. Soll,” the individual is a member of CyberAv3ngers, a group directly linked to the IRGC-CEC. He is believed to be the operator behind the IOControl malware, designed to target SCADA/ICS systems. The malware was allegedly deployed in 2023 and 2024 against water utility infrastructure in both the United States and Israel.