logo

Hackers Lay in Wait, Then Knocked Out Iran Ship Comms

ID: 305ab42b-c202-55a8-b2a1-2bce472bfc29

STIX ID: report--305ab42b-c202-55a8-b2a1-2bce472bfc29

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-08-25

Date Updated: 2026-05-08

Author: Jai Vijayan, Contributing Writer

...
...

Lab-Dookhtegan claims to have compromised Fanava Group and gained root access to satellite communications on Iranian vessels, disabling iDirect/Falcon, bricking automatic identification system (AIS) and voice links, and overwriting multiple storage partitions on dozens of cargo ships and tankers — causing weeks-to-months of downtime per vessel. The attackers had persistent access since May, could have eavesdropped on calls, and previously leaked materials tied to APT34; the incident underscores supply-chain risk to maritime critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.