IRISL
Incident posture
Timeline
Summary
A threat group known as "Lab Dookhtegan" conducted a sophisticated supply-chain cyberattack against an Iranian satellite communications provider, Fanava, to gain access to Iran's state-owned fleet of tankers. After penetrating the provider's systems, the attackers obtained fleetwide control over ship-to-shore VOIP services, disrupting communications between vessels and shore-based offices or port officials. While exploiting this access, the group stole internal corporate documents belonging to Iranian state firms NITC and IRISL and subsequently leaked the materials online. Upon completing their data theft, the attackers destroyed the ships' onboard modems by overwriting partitioned memory, rendering the hardware irrecoverable through software fixes and necessitating physical replacement of the equipment.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In 2025, the Iranian state-owned fleet of tankers was the target of a sophisticated cyberattack carried out by a threat group known as "Lab Dookhtegan," which translates to "sewn lips." The attackers systematically targeted Fanava, an Iranian satcom provider, exploiting vulnerabilities high up the digital supply chain that served Iran's state-owned tanker fleet. By penetrating Fanava, the threat group obtained fleetwide control over ship-to-shore VOIP services, severely disrupting the ability of affected vessels to communicate with their home office and with port officials. This breach represented a significant compromise of shoreside infrastructure, providing the attackers with broad reach across multiple vessels operating under Iranian ownership.
While in possession of unauthorized access to the ships' networks, the Lab Dookhtegan group stole corporate documents belonging to Iranian state firms NITC and IRISL and subsequently released them online. The theft and public exposure of internal corporate records represented a major data breach for these organizations, exposing sensitive operational and business information to public scrutiny. In addition to the data theft, the threat group carried out destructive actions against the targeted fleet. Once the attackers concluded their mission of exploiting the access they had obtained, they destroyed the ships' modems by overwriting partitioned memory. This destructive action rendered the communication hardware inoperable and required physical replacement of the equipment, adding a costly and time-consuming hardware remediation effort to the operational fallout of the incident.
The combined impact of the attack included the theft and online release of corporate documents from NITC and IRISL, the disruption of ship-to-shore VOIP communications across the Iranian state-owned tanker fleet, and the physical destruction of vessel modems. Recovery from the incident required the replacement of damaged hardware, while the exposure of stolen documents created lasting reputational and informational consequences for the affected Iranian state firms. The attack demonstrated the vulnerability of shoreside supply chain components, as the compromise of a single satcom provider enabled fleetwide operational disruption and data theft.
Sources
Sources available to members: 1 source.