Yesterday, a new hacking tool was released on Telegram , reportedly used by Iranian hackers. This is not the first time such a leak has happened. In April, six other Iranian tools were leaked, and they were leaked by the same person who revealed the new tool. At that time, this person, who goes by the name Lab Dookhtegan, spoke about the victims (that is, those on whom the tools had been used) but also about the real identities of the Iranian government hackers ![]()
The new tool is called Jason and, like the previous ones, was released on Telegram.
A security researcher, Omri Segev Moyal, said that it is a GUI utility that can be used to brute-force attacks on Microsoft Exchange email servers, using combinations of usernames and passwords.
According to the researcher, the Jason tool was created in 2015. This means that Iranian hackers have been using it for four years to carry out attacks.
The previous six tools, which Lab Dookhtegan had published, belonged to an Iranian espionage group known by various names, such as APT34, Oilrig, or HelixKitten. It is believed that members of the Iranian Ministry of Intelligence are part of this group.
The tools that were released in April had been identified in previous attacks. However, the Jason tool is something new for the researchers who analyzed it.
Since April, Lab Dookhtegan has been continuously publishing information about Iranian hackers, such as their names, social media profiles , phone numbers, and photos.
As for the information that exists about Lab Dookhtegan, it is probably a member of a foreign intelligence service that is trying to expose the hacking efforts of the Iranians and to destroy the espionage operations of the Iranian government.
In May, another individual published information about another Iranian hacker group called MuddyWater. The activities of the MuddyWater group have been linked to an Iranian organization known as the Rana Institute.
