APT34
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Lab Dookhtegan is an Iranian hacktivist group that operates under the aliases Lab Dookhtegan and Tapandegan. The group is based in Iran and has conducted operations aimed at exposing alleged abuses by the Iranian government and revealing internal details of state‑linked cyber‑espionage actors. Its activities are carried out primarily through public disclosures on messaging platforms such as Telegram. The collective describes itself as seeking to highlight the repressive actions of the regime and to undermine its cyber capabilities.
The group’s targeting focuses on Iranian governmental institutions and on the infrastructure of the Iranian state‑sponsored APT34/OilRig collective. By leaking video from a Tehran prison’s CCTV system, it directed attention to the Evin detention facility where political detainees are held. In parallel, it has disclosed internal data, tools and personnel information belonging to APT34, which conducts cyber‑espionage against Middle‑ Eastern government and commercial entities. The stated purpose of these actions is disruption and exposure rather than financial gain.
Typical tactics include breaching internal surveillance networks to obtain and exfiltrate visual material, as demonstrated in the Evin prison incident. The group also distributes brute‑force utilities such as the Jason email hijacking tool, which attempts to guess passwords for Microsoft Exchange accounts. It has released PowerShell‑based backdoors identified as Poison Frog and Glimpse, and a suite of web shells including HyperShell, HighShell, Fox Panel and Webmask. These toolsets are often accompanied by credential lists and configuration details taken from compromised targets.
Notable operations consist of the August 2021 breach of Evin prison’s CCTV cameras, which yielded footage of inmate abuse that was shared with international media, and the March 2019 Telegram‑based leak of APT34’s internal infrastructure, source code, and personal data of alleged Ministry of Intelligence staff. While the group denies direct involvement in the prison leak, the allied Tapandegan alias helped amplify the released videos. Attribution assessments place the actors within the Iranian opposition milieu, with some analysts suggesting they may be current or former insiders opposed to the regime’s cyber‑operations. No public evidence links the group to a foreign state sponsor or to a criminal‑for‑profit enterprise.
Incidents
Attributed incidents are available to members.
2 incidents