CSIDB logo
Incident

Fanava

Incident posture

Attack window
2025
Location
Iran
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:37

Linked entities

Victim
Fanava
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The "Lab Dookhtegan" threat group conducted a supply chain cyberattack against Iranian satcom provider Fanava, penetrating its systems to gain fleetwide control over ship-to-shore VOIP services for Iranian state-owned tankers. While inside the network, the attackers stole corporate documents belonging to NITC and IRISL and released them publicly. After completing their objective, the group destroyed the vessels' modems by overwriting partitioned memory, requiring physical hardware replacement to restore connectivity and forcing the affected tankers to rely on alternative communication methods with their home offices and port authorities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

The incident centered on the Iranian satellite communications provider Fanava, which was systematically targeted by a threat group known as "Lab Dookhtegan" (translated as "sewn lips"). The attack was notable for occurring high up in the digital supply chain, giving the threat actors reach across an entire fleet of vessels rather than requiring individual compromises of each ship. Fanava served as a satcom provider for Iranian state-owned tanker companies, and penetrating this single entity allowed the attackers to leverage access to downstream maritime operations. The timing of the campaign placed it within a broader surge in maritime cyberattacks during 2025, when Cytur reported that such incidents had doubled compared to the previous year.

Once inside Fanava's systems, the Lab Dookhtegan group obtained fleetwide control over ship-to-shore Voice over Internet Protocol (VOIP) services. This capability enabled the attackers to interfere with or monitor communications between vessels at sea and their home offices, as well as with port officials. By exploiting their position at the satcom provider level, the threat actors were able to affect multiple vessels operated under Iranian state firms NITC and IRISL simultaneously, rather than needing to compromise each ship's individual communications systems. While holding access to the ships' networks, the attackers also stole corporate documents belonging to NITC and IRISL, which were subsequently released online.

After completing their intelligence-gathering and access objectives, the Lab Dookhtegan group moved to a destructive phase. The attackers destroyed the ships' modems by overwriting partitioned memory, rendering the hardware unusable. Because the damage was physical in nature to the storage components, recovery required physical replacement of the modem hardware rather than a software-based restoration. This destructive component elevated the incident beyond a typical data theft or ransomware scenario and demonstrated the attackers' willingness to cause lasting operational disruption. The combination of intelligence theft, communications manipulation, and physical destruction of equipment represented a worst-case scenario for maritime supply chain attacks.

Sources

Sources available to members: 1 source.

CSIDB