Threats Feed|APT34|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date06/06/2019

A Deep Dive into APT34's Leaked Tool: Analyzing the Jason Project

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Brute-force,Credential stuffing
  • Attack Complexity: Low
  • Threat Risk: High Impact/Low Probability

Threat Overview

Marco Ramilli provides an independent technical analysis of the Jason Exchange Mail BF tool (v7.0), leaked by Lab Dookhtegan on June 3, 2019, as part of the APT34 tool exposure on Telegram. Jason is a graphical .NET tool designed to brute-force Microsoft Exchange accounts and harvest email addresses and account credentials. It was distributed in a ZIP container containing three components: Jason.exe (the GUI frontend), Microsoft.Exchange.WebService.dll (version 15.0.0.0, dated to 2012 despite a last-available 2015 release — suggesting the tool may have been initially developed or frozen around that period), and a password pattern library (PassSample folder with Year.txt, numspecial.txt, num4.txt, num4special.txt, and username/password list files). Three attack modes are selectable: EWS (Exchange Web Services), OAB (Offline Address Book), or both simultaneously; a DNS domain discovery function is also present in the code for auto-detecting Exchange servers. The tool supports configurable thread counts for attack speed tuning. Ramilli notes the developer implemented extensive exception-handling protections — checks for null bytes, variable validation, object index and key guards — which he interprets as either targeting non-technical end users or reflecting professionally-trained development practices. He identifies weak code style similarities with other APT34 tools (Glimpse, WebMask) in exception protection patterns and file logging conventions, but explicitly withholds personal attribution, noting these similarities are insufficient for confident APT34 attribution beyond the trusted source (Lab Dookhtegan). The PDB path (D:\Project\Jason\obj\Release\Jason.pdb) and version string "Jason - Exchange Mail BF - v 7.0" confirm the internal project name. Ramilli publishes a YARA rule (_APT34_Jason) with 20 strings for detection. Source URL is no longer accessible; this analysis is based on the archived PDF attachment.

Extracted IOCs

  • 0cf66c68c265191d36fc9648b4ef879a80be0c3b6da289de5891ede1554de48d
  • 9762444b94fa6cc5a25c79c487bbf97e007cb680118afeab0f5643d211fa3f78
download

Tip: 2 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

APT34Lab Dookhtegan Exposes APT34's Email Hacking Tool: The Silent Threat of 'Jason'

Source: Telsy - June 2019

Detection (one case): 9762444b94fa6cc5a25c79c487bbf97e007cb680118afeab0f5643d211fa3f78

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: APT34's Jason Exchange Brute-Force Tool

Jason is a graphical .NET tool designed to brute-force Microsoft Exchange accounts and harvest emails and credentials. It was leaked by Lab Dookhtegan on June 3, 2019, as part of a Telegram-based exposure of what were claimed to be APT34 tools. Marco Ramilli analyzed it independently and found weak code style similarities with other confirmed APT34 tools, though he notes these are insufficient for definitive attribution. The tool became especially significant when Yoroi and Telsy later assessed that APT34 likely used Jason to gain Exchange credentials before deploying the Karkoff and MailDropper implants against Lebanon's government in 2020.

Jason was leaked as part of the Lab Dookhtegan APT34 tool dump on Telegram. Ramilli identifies weak code style similarities with confirmed APT34 tools — similar exception-handling patterns and file logging conventions seen in Glimpse and WebMask — but explicitly states he cannot personally attribute Jason to APT34 based on code analysis alone. Attribution to APT34 rests primarily on the trusted source of the leak (Lab Dookhtegan) rather than technical evidence. Later use of Jason in the 2020 Lebanon Karkoff/MailDropper campaign provides stronger circumstantial evidence of APT34 ownership.

Jason is designed for credential theft and email collection. It brute-forces Exchange account credentials, then uses valid credentials to harvest emails and account information from targeted mailboxes. The downstream purpose — as seen in the 2020 Lebanon campaign — is to obtain Exchange credentials that can then be hardcoded into implants like MailDropper, enabling them to use compromised government Exchange servers as covert C2 infrastructure.

Jason v7.0 supports three attack modes: EWS (Exchange Web Services), OAB (Offline Address Book), or both simultaneously. It also includes a DNS domain discovery function that can auto-detect the Exchange server from a domain name. The attack is configured through a GUI — the operator provides the Exchange address, selects the attack method, and provides username and password lists or patterns. Thread count is configurable to balance attack speed and noise. The bundled password library includes year-based patterns, numeric sequences, special character patterns, and username-derived templates.

Based on the binary compilation date (January 2019) and the version string "Jason - Exchange Mail BF - v 7.0," the tool was compiled shortly before the leak. However, the use of a Microsoft.Exchange.WebService.dll version from 2012 (v15.0.0.0, with the last available version dating to 2015) suggests the project may have been initially developed years earlier and maintained over time. The high version number (v7.0) is consistent with long-term iterative development.

The Lab Dookhtegan leaks in 2019 exposed a range of tools attributed to APT34, including Jason, Glimpse, WebMask, and others. The leaks included tool source code, operator names, victim lists, and internal project files, causing significant disruption to APT34 operations. Jason's public exposure meant defenders could now develop signatures and protections for the tool — contributing to the YARA rule published by Ramilli. The leak also gave subsequent researchers like Yoroi and Telsy the context to link Jason to the 2020 Lebanon Exchange credential brute-force operations.

Jason's importance is as a precursor tool — a credential acquisition step that enables more destructive follow-on operations. Once Jason obtains valid Exchange credentials, those credentials can be hardcoded into implants like MailDropper or Karkoff, enabling attackers to use a victim's own government Exchange server as a covert C2. This creates a particularly difficult detection problem: the C2 traffic is encrypted Exchange email that originates from a legitimate institutional server, blending completely with normal organizational communications.

Deploy the YARA rule published by Ramilli (_APT34_Jason) — it includes 20 distinctive strings such as the PDB path, version string "Jason - Exchange Mail BF - v 7.0," method names (get_PasswordPattern, get_PasswordFile), and success indicators ("Total Login Successful :") — to detect Jason binaries. Monitor Exchange EWS and OAB endpoints for high-frequency authentication attempts from single IPs, which is the behavioral signature of Jason's attack. Block or rate-limit external EWS/OAB access where not required. Enforce MFA on all Exchange accounts — this is the most effective countermeasure, as Jason relies entirely on password-based authentication. Use the published file hashes to hunt for Jason in endpoint telemetry.

About Affiliation
APT34
APT34 is Mandiant's designation for the Iranian MOIS-linked threat cluster known as OilRig. Active since at least 2014, Mandiant identified APT34 as an advanced persistent threat focused on long-term espionage against government, energy, and financial organizations in the Middle East. Mandiant has documented the group's evolution over more than a decade, including its use of DNS-based command and control, LinkedIn-based social engineering lures, and a continuously expanding custom malware arsenal. APT34 remains one of the most thoroughly documented Iranian state-sponsored actors in public threat intelligence.
View APT34's Insights