CSIDB logo
Incident

NITC

Incident posture

Attack window
2025
Location
Iran
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:42

Linked entities

Victim
NITC
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyber threat group known as Lab Dookhtegan ("sewn lips") conducted a high-level supply chain attack against Fanava, an Iranian satcom provider, gaining fleetwide access to the digital networks of Iranian state-owned tankers. While inside the compromised infrastructure, the attackers stole corporate documents belonging to Iranian shipping firms, which were subsequently leaked online. The group also obtained remote control over ship-to-shore VOIP services, disrupting communications with the home office and port officials. After completing its data theft objectives, Lab Dookhtegan destroyed vessel modems by overwriting partitioned memory, rendering the hardware unusable and requiring physical replacement.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The National Iranian Tanker Company (NITC) was among the corporate entities affected by a supply chain cyberattack carried out by a threat actor known as "Lab Dookhtegan," meaning "sewn lips" in Farsi. The attack targeted Fanava, an Iranian satcom provider that serves the country's state-owned tanker fleet, exploiting a high-level position in the digital supply chain to reach downstream vessel communications. By penetrating Fanava's systems, the threat group obtained fleetwide control over ship-to-shore VOIP services used by Iranian tankers, including those operated by NITC. This foothold in the communications infrastructure gave the attackers an entry point into the networks of the vessels and their operating companies, allowing them to move from a shoreside provider into the operational environment of the fleet.

Once inside the network perimeter, Lab Dookhtegan accessed and exfiltrated corporate documents belonging to NITC, as well as those of another Iranian state-owned shipping line, the Islamic Republic of Iran Shipping Lines (IRISL). The stolen material was subsequently released online, exposing internal corporate information of the two firms. The attack did not end with data theft. While still in possession of access to the ships' networks, the threat group destroyed the vessels' modems by overwriting partitioned memory, a destructive action that required physical replacement of the hardware to restore communications. The combination of fleetwide communications disruption, document theft and publication, and permanent damage to onboard hardware made the incident one of the more severe maritime cyberattacks reported during 2025, illustrating how a compromise at a single satcom provider can cascade into operational, informational, and physical consequences across an entire fleet.

The incident followed a broader pattern observed by the Korean security firm Cytur, which reported that maritime cyberattacks doubled in 2025, driven largely by an increase in malware and distributed denial of service incidents. Attackers continued to gain initial access through common vectors such as phishing emails aimed at crewmembers, unprotected public WiFi used by shipboard personnel, and infected USB drives introduced either deliberately or by mistake. However, the NITC-focused operation demonstrated a more advanced approach, in which the threat actor moved up the digital supply chain rather than attacking individual vessels directly. By compromising Fanava, Lab Dookhtegan was able to position itself to affect a large portion of Iran's state-owned tanker fleet simultaneously, obtaining useful information about onboard systems and, in some cases, the means to remotely affect vessel equipment.

The impacts of the attack on NITC spanned several categories. Communications between the tankers and the home office, as well as between the vessels and port officials, were disrupted through the hijacking of the ship-to-shore VOIP services. Corporate documents belonging to NITC were stolen and released publicly, a form of data breach and exposure that can have reputational and operational consequences for a state-owned shipping operator. Onboard modems were physically destroyed, meaning that recovery required not just software remediation but the procurement and installation of replacement components, prolonging the disruption. The attackers' ability to overwrite partitioned memory on the modems showed a destructive intent beyond espionage or financial extortion, distinguishing the operation from typical ransomware or data-theft campaigns reported elsewhere in the maritime sector during the same period.

The sequence of events began with Lab Dookhtegan's targeting of Fanava, the satcom provider whose services underpinned communications for Iranian state-owned tonnage. After gaining access to Fanava's systems, the attackers leveraged that position to reach the networks of vessels using the provider, including NITC tankers. They then obtained fleetwide control over ship-to-shore VOIP, used that access to steal corporate documents from NITC and IRISL, published the stolen material, and finally destroyed the modems by overwriting their partitioned memory, rendering the hardware inoperable and necessitating physical replacement. The source article does not specify how the initial intrusion into Fanava was achieved, nor does it provide a timeline of detection, containment, or recovery steps taken by NITC, Fanava, or Iranian authorities. The information available is limited to the attacker's identity, the target, the methods used, and the consequences described above, without further detail on internal response actions.

The broader context of the incident, as documented by Cytur, indicates that maritime cyberattacks in 2025 increasingly targeted operational technology and supply chain providers, with ransomware and data theft observed frequently in high-traffic regions such as Asian waters and major hub ports. The Lab Dookhtegan operation against Iranian tonnage, including NITC, exemplified the supply chain risk highlighted by Cytur: a shoreside provider's compromise can give attackers useful information about systems or even remote access at a fleet level, enabling outcomes ranging from data theft to the destruction of equipment. The article does not record any official response statement from NITC, any ransom demand associated with this specific operation, or any law enforcement action taken against Lab Dookhtegan, leaving the documented consequences confined to communications disruption, document exposure, and modem destruction at the hands of the threat group.

Sources

Sources available to members: 1 source.

CSIDB