Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them

The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad.

Iranian APTs

The US this week announced charges against 17 members of the Iran-based company Mabna Institute for hacking into hundreds of organizations in the US and abroad.

According to a 14-count superseding indictment, Mabna Institute was founded in 2013 to help universities and research organizations in the country steal non-Iranian scientific resources.

It has targeted universities in the US (144) and abroad (178), private companies in the US (42) and abroad (11), five government agencies in the US, and at least two NGOs, stealing over 31 terabytes of academic data and intellectual property, as well as employee email accounts.

The 17 defendants charged over these intrusions acted on behalf of the Islamic Republic of Iran’s Islamic Revolutionary Guard Corps (IRGC), the Justice Department says.

According to the indictment, the Mabna Institute was founded by Gholamreza Rafatnejad and Ehsan Mohammadi, and employed, contracted, and affiliated with Abdollah Karima (aka Vahid Karima), Mostafa Sadeghi, Seyed Ali Mirkarmi, Mohammed Reza Sabahi, Roozbeh Sabahi, Abuzar Gohari Moqadam, Sajjad Tahmasebi, Saeid Houshyar, Behzad Mesri (aka Skote Vahshat), Manouchehr Hashemloo, Keyvan Fayaz (aka Achilles, The Joker, and bc.monster), Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian, and Mojtaba Galekuhi (aka Mojtaba Ghaleh Koui).

The Mabna Institute allegedly conducted cyber intrusions on behalf of both the Iranian government and private organizations.

Advertisement. Scroll to continue reading.

Through the Rewards for Justice program (RFJ), the US government is offering rewards of up to $10 million for information leading to the arrest of Mesri, Galekuhi, Kahzadian, Fayaz, and Ballojeh.

According to the superseding indictment, the defendants targeted over 100,000 professors worldwide and successfully compromised roughly 8,000 professor email accounts at 144 universities in the US and 178 institutions in Australia, Canada, China, Denmark, Finland, Germany, Ireland, Israel, Italy, Japan, Malaysia, Netherlands, Norway, Poland, Saudi Arabia, Singapore, South Korea, Spain, Sweden, Switzerland, Turkey, the United Kingdom, and other countries.

Using stolen credentials, the hackers accessed the victim professors’ accounts and used them to exfiltrate data and documents across engineering, medical, technology, and other fields of research and academic disciplines.

The defendants, the indictment alleges, also sold the stolen data through Megapaper and Gigapaper, two companies affiliated with Abdollah Karima.

Additionally, the defendants targeted various other private and government agencies, including HBO in a $6 million extortion attempt.

Related: Snowflake Hacker Pleads Guilty in US Court

Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison

Related: Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

Related: Two Scattered Spider Hackers Sentenced to Jail in UK

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.