17 Iranians Indicted for Massive Cyber Theft Campaign
Over 100,000 educators globally fell victim to relentless hackers who spent years plundering academic research, proprietary books, and other invaluable intellectual property. The United States indicted 17 Iranian nationals affiliated with the Mabna Institute for orchestrating this massive cyber theft campaign. These sophisticated cybercriminals systematically exfiltrated highly sensitive data primarily to benefit the Islamic Revolutionary Guard Corps and various other Iranian state-sponsored entities.
The Scale of the Mabna Institute Operation
According to the United States Department of Justice, the Mabna Institute has operated clandestinely since at least 2013. During this extensive period, the malicious actors successfully compromised 144 American universities and 178 international academic institutions. Furthermore, their expansive campaign targeted no fewer than 53 private corporations, five federal and regional United States government agencies, and numerous non-governmental organizations. Consequently, they breached approximately 8,000 educator accounts, successfully exfiltrating an astonishing 31.5 terabytes of proprietary academic and instructional material.
Tactics: Spear Phishing and Credential Harvesting
The primary weapon in their formidable arsenal was highly targeted spear phishing. The campaign operatives meticulously compiled exhaustive lists of educators, subsequently dispatching deceptive emails to harvest their login credentials. Utilizing these compromised passwords, the attackers seamlessly infiltrated university networks. Once inside, they systematically downloaded vast quantities of academic journals, doctoral dissertations, and electronic books. Their massive data haul encompassed vital research spanning engineering, medicine, advanced technologies, and the social sciences.
Monetizing Stolen Intellectual Property
These purloined materials directly generated substantial illicit profits. The formal indictment alleges that the hackers brazenly sold the stolen data through websites such as Megapaper.ir and Gigapaper.ir. Clients residing within Iran could easily purchase these academic materials. Alternatively, they could secure direct access to the electronic libraries of foreign universities via the compromised accounts of unsuspecting educators.
Beyond Universities: Corporate and Government Targets
The Mabna Institute did not restrict its malicious activities solely to the academic sector. The hackers successfully penetrated the email systems of employees at the United States Department of Labor, the Federal Energy Regulatory Commission, and the state governments of Hawaii and Indiana. Their reach even extended to prominent international organizations, including the United Nations and UNICEF.
Furthermore, specific members of this group are implicated in a devastating cyberattack against HBO, culminating in a brazen extortion demand of approximately six million dollars in Bitcoin. Other malicious operations targeting corporations and government structures resulted in severe financial damages, with investigation and recovery costs exceeding twenty million dollars.
Expanding the 2018 Indictment
This current legal action significantly expands upon an initial indictment handed down in 2018. At that time, American authorities officially named nine individuals associated with the Mabna Institute. Now, prosecutors have added eight new defendants to the comprehensive case. The accused face severe charges, including computer fraud, wire fraud, aggravated identity theft, and criminal conspiracy. Specific counts carry maximum penalties of up to 20 years in federal prison; however, the court has yet to convict the defendants.
Simultaneously, the United States Department of State offered a substantial reward of up to ten million dollars for information leading to the precise location of five key defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh. The Federal Bureau of Investigation is actively spearheading this complex investigation, receiving crucial assistance from the United Kingdom’s National Crime Agency and various other American federal agencies.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.