{"id":6419,"date":"2025-08-26T10:03:40","date_gmt":"2025-08-26T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/26\/hackers-sabotage-iranian-ships-using-maritime-communications-terminals-in-its-mysql-database\/"},"modified":"2025-08-26T10:03:40","modified_gmt":"2025-08-26T10:03:40","slug":"hackers-sabotage-iranian-ships-using-maritime-communications-terminals-in-its-mysql-database","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/26\/hackers-sabotage-iranian-ships-using-maritime-communications-terminals-in-its-mysql-database\/","title":{"rendered":"Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database"},"content":{"rendered":"<p>    Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated campaign of cyber sabotage unfolded against Iran\u2019s maritime communications infrastructure in late August 2025, cutting off dozens of vessels from vital satellite links and navigation aids.<\/p>\n<p>Rather than targeting each ship individually\u2014a logistical nightmare across international waters\u2014the attackers infiltrated Fanava Group, the IT provider responsible for satellite communications to Iran\u2019s sanctioned tanker fleets.<\/p>\n<p>By compromising the company\u2019s outdated iDirect Falcon terminals, they gained root access to Linux systems running kernel 2.6.35 and mapped the entire constellation of vessels through a centralized <a href=\"https:\/\/cybersecuritynews.com\/mysql-copy-database-make-clones-of-your-databases-with-ease\/\" target=\"_blank\" rel=\"noreferrer noopener\">MySQL database<\/a>.<\/p>\n<p>The initial breach vector appears to have exploited unpatched vulnerabilities in legacy Falcon management consoles, allowing the threat actors to execute privileged commands and exfiltrate network mappings.<\/p>\n<p>Once inside, they harvested modem serial numbers, network IDs, and IP phone system configurations in plain text, including credentials such as \u201c1402@Argo\u201d and \u201c1406@Diamond.\u201d<\/p>\n<p>These details were then weaponized to orchestrate a synchronized blackout: email and FBB SIM communications failed, automated weather updates ceased, and port coordination signals vanished almost instantaneously.<\/p>\n<p>Nariman Gharib researchers <a href=\"https:\/\/blog.narimangharib.com\/posts\/2025%2F08%2F1755854831605?lang=en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that the campaign, dubbed Lab-Dookhtegan, was not a one-off disruption.<\/p>\n<p>Email logs dating back to May revealed persistent access and periodic \u201cNode Down\u201d tests, confirming that the attackers maintained control over the networks for months before launching a destructive finale.<\/p>\n<p>On August 18, they executed a \u201cscorched earth\u201d sequence, overwriting multiple storage partitions on satellite modems with zeroed data, rendering remote recovery impossible.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgnY4X5gYzvGqHe8C5Skqf64ZFwI4gsBfENFW-QK89zpfJUh8Y0_7UaI7PI7U41x0jpO9NU7EXDfoatYls_uAZKBFm-kWF2gW9nlwK12nQ3I0NEoAXJ4ISz_hV8QqLISgcgglSyYgQO9AHHhxW46w7M15Qw2R2uU9zYXvXwX_ESLgE2nvLrh5BB__h3dgs\/s16000\/FANAVA%2520%28Source%2520-%2520Nariman%2520Gharib%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">FANAVA (Source \u2013 Nariman Gharib)<\/figcaption><\/figure>\n<\/div>\n<p>By crippling Iran\u2019s sanctioned fleets\u2014NITC and IRISL\u2014at a time when covert oil transfers to China intensify, the attackers dealt a blow to the country\u2019s sanctions-evasion capabilities.<\/p>\n<p>Without communication links, tankers risk drifting off-course or becoming easy targets for boarding and seizure. The operation\u2019s precision underscores a deep <a href=\"https:\/\/cybersecuritynews.com\/morphing-meerkat-phaas-using-dns-reconnaissance\/\" target=\"_blank\" rel=\"noreferrer noopener\">reconnaissance<\/a> phase, allowing the threat actors to deliver maximally disruptive payloads at the worst strategic moment.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>The malware\u2019s infection mechanism relied on a multi-stage approach: initial access through unprotected management ports, lateral movement via SSH keys harvested from MySQL dumps, and deployment of destructive scripts.<\/p>\n<p>After gaining root on a compromised Falcon console, the attackers executed commands akin to:-<\/p>\n<pre class=\"wp-block-code\"><code>dd if=\/dev\/zero of=\/dev\/mmcblk0p1 bs=1M\ndd if=\/dev\/zero of=\/dev\/mmcblk0p2 bs=1M<\/code><\/pre>\n<p>These commands systematically wiped primary storage partitions and recovery slices, ensuring the terminal\u2019s firmware and configurations were irrecoverable without physical intervention.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjwef7mZp4ZVtrdKbK-wE3BW7ejbf0cF1HOdjnDCOggJP4GYjZ0hCXcbacSFb5nwVBWxSq1gbF2Azmjgk7kyRpeACCL6_VZu5iue5USg8nNFXh4l1-u2jEQeeg75HQhKp3NQ51mbfCBwScrc7SwRx8PdcI-ncDHGb2MSy5ttbacVX852cBxp1vCvV6GPJA\/s16000\/IP%2520addresses%2520and%2520passwords%2520in%2520plain%2520text%2520%28Source%2520-%2520Nariman%2520Gharib%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">IP addresses and passwords in plain text (Source \u2013 Nariman Gharib)<\/figcaption><\/figure>\n<\/div>\n<p>Simultaneously, SQL queries extracted the fleet blueprint:-<\/p>\n<pre class=\"wp-block-code\"><code>SELECT serial_number, vessel_name, network_id\nFROM modems;<\/code><\/pre>\n<p>Armed with this data, the attackers automated <a href=\"https:\/\/cybersecuritynews.com\/credential-theft-risks\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential<\/a> injection and shutdown sequences across 64 vessels with a single orchestration script.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjrjfBzg0obE8pyatM42Hc-iH1Rl7drQzhXuByp0hIQe8SFwtaz5CqlQhlrDBkTV5p41StnDUMjSwxZKhkaq8lh2LKRqcgD4ZhCUIfk_qdjt1VeTcBY-BrXIJBnoN7cRTNOsEznz4skhFBI83tgsz6J4OKxc23yUlpE16ewcgV4I54eJKym4PcmIHAcZTU\/s16000\/PoCs%2520%28Source%2520-%2520Nariman%2520Gharib%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">PoCs (Source \u2013 Nariman Gharib)<\/figcaption><\/figure>\n<\/div>\n<p>By embedding malicious cron entries, they achieved both persistence and timed execution, triggering the blackout at a moment calculated to maximize operational chaos.<\/p>\n<p>This infection chain highlights the importance of isolating management interfaces and enforcing strict patch regimes on critical satellite communication systems.<\/p>\n<p class=\"has-text-align-center has-background\" id=\"block-6a896d87-08ff-4ae3-807c-e602cd97752b\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-sabotage-iranian-ships-using-maritime-communications\/\">Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-sabotage-iranian-ships-using-maritime-communications\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database A sophisticated campaign of cyber sabotage unfolded against Iran\u2019s maritime communications infrastructure in late August 2025, cutting off dozens of vessels from vital satellite links and navigation aids. Rather than targeting each ship individually\u2014a logistical nightmare across international waters\u2014the attackers infiltrated Fanava Group, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6419","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6419"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6419"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6419\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6419"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6419"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6419"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}