Lab Dookhtegan Exposes APT34's Email Hacking Tool: The Silent Threat of 'Jason'
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Brute-force,Credential stuffing
- Attack Complexity: Low
- Threat Risk: High Impact/Low Probability
Threat Overview
Telsy published the first public analysis of Jason on June 3, 2019 — the same day Lab Dookhtegan released it on Telegram — making this the earliest documented response to the leak. Jason is a .NET graphical tool designed to brute-force Exchange email accounts using OAB and EWS methods, with support for user/password lists loaded from text files and configurable multi-threading. The tool was not flagged by any VirusTotal engine at time of analysis; Telsy explicitly notes this and calls on security vendors to classify Jason and similar hacking tools as potentially malicious. Scan results are written to out-[datetime].txt files; debug and activity logs are saved to log.txt. Telsy characterizes the tool as "simple old-style appearing but potentially very effective" and notes that multiple versions appear to have been released over time, with version 7.0 likely dating to early 2019. On June 4, 2019, Telsy published a tlp:white YARA detection rule for Jason on their public GitHub repository (github.com/telsy-cyberops/research/blob/master/APT34/YARA), available for immediate use by defenders.
Extracted IOCs
- 172c004ec5ecac3c4b13336200c693e4
- 98cb0ef1ecbb683d0da19a17b5739f25
- 1cd310cb0293e21374e3dc01607a09106f2d1d74
- 3980b5ea292e6cd17e6717475ac1485960f5a6f2
- 0fe8025b9a6e6907d0be4810fbfbc61f1aee3ba14e855bbf5c35f0f3b8b913ce
- 9762444b94fa6cc5a25c79c487bbf97e007cb680118afeab0f5643d211fa3f78
Tip: 6 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 6 file hash) to this threat have been found.
Overlaps
Source: Marco Ramilli - June 2019
Detection (one case): 9762444b94fa6cc5a25c79c487bbf97e007cb680118afeab0f5643d211fa3f78
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions: APT34's Jason Tool — Telsy's First-Response Analysis
Telsy was among the first to analyze Jason — publishing the same day Lab Dookhtegan leaked it on Telegram. Jason is a .NET graphical tool for brute-forcing Microsoft Exchange email accounts using OAB and EWS methods, with configurable user/password lists and multi-threading. At time of publication, no VirusTotal engine flagged it as malicious. Telsy calls on security vendors to classify such hacking tools as potentially malicious even though the tool itself doesn't directly compromise a system — it's a credential theft enabler.
Jason was leaked by Lab Dookhtegan as part of the APT34 tool exposure on Telegram. Attribution to APT34 rests on the trusted source of the leak. Telsy's concurrent analysis of the same group's MailDropper implant (2020) later confirmed that APT34 used Jason to brute-force Exchange credentials that were then hardcoded into the MailDropper backdoor, providing real-world evidence of Jason being operationally deployed by APT34.
Jason is a credential theft and email harvesting tool. It brute-forces Exchange accounts to obtain valid credentials, which can then be used to access and harvest emails and account information from targeted mailboxes. In APT34's operational chain — as seen in the 2020 Lebanon campaign — the obtained credentials are hardcoded into implants like MailDropper, enabling the malware to use the victim's own government Exchange server as a covert C2 channel.
Telsy confirmed zero VirusTotal detections for Jason.exe at time of publication — a direct consequence of the tool being a GUI brute-force utility rather than malware that deploys a payload or creates persistence. This makes it harder for traditional antivirus to flag as malicious. Telsy's call to action for security vendors to classify such hacking tools as potentially malicious reflects a broader gap in endpoint protection: tools designed for credential theft often evade detection because they don't exhibit traditional malware behaviors.
Jason writes scan results to out-[datetime].txt files and debug/activity logs to log.txt in the working directory. These are forensic artifacts — if an analyst finds either file type in unexpected locations on a system, it may indicate Jason was recently run on that machine. The datetime-stamped output file naming also provides a rough indication of when the tool was used.
The significance is in Jason's role as a precursor tool in a multi-stage attack chain. APT34 uses Jason to obtain Exchange credentials, then hardcodes those credentials into implants like Karkoff and MailDropper. Those implants use the compromised Exchange server as their C2 — routing all attack communications through the victim organization's own email infrastructure. This creates a C2 channel that is effectively invisible: the traffic is encrypted Exchange email originating from a legitimate institutional server, indistinguishable from normal organizational communications without deep Exchange audit log inspection.
The Lab Dookhtegan leaks exposed multiple APT34 tools, operator identities, and victim lists in 2019, causing significant disruption to the group. For defenders, the leaks provided rare visibility into an active Iranian state APT toolkit. Jason's exposure allowed the community to develop YARA rules and detection signatures — within 24 hours of the leak, Telsy had published a detection rule, and Marco Ramilli followed two days later with a 20-string YARA rule. The leaks also gave researchers the context to connect Jason to subsequent APT34 operations against Lebanon's government in 2020.
Deploy both published YARA rules: Telsy's tlp:white rule on GitHub (github.com/telsy-cyberops/research/blob/master/APT34/YARA) and Marco Ramilli's 20-string _APT34_Jason rule. Hunt for out-*.txt and log.txt files in unexpected directories as forensic artifacts of Jason execution. Monitor Exchange EWS and OAB endpoints for high-frequency authentication attempts — this is the behavioral signature of Jason's attack. Enforce MFA on all Exchange accounts. Block or rate-limit external EWS/OAB access where not required. Use all six published file hashes to scan endpoints.