U.S. prosecutors have unsealed a 14-count superseding indictment against 17 alleged members of the Iran-based Mabna Institute, accusing them of carrying out a years-long cyber campaign against universities, companies, government agencies and other organizations around the world.
According to the indictment, the Mabna Institute conducted coordinated cyber intrusions beginning around 2013 and targeted 144 universities in the United States, 178 universities in other countries, at least 42 U.S. private-sector companies, 11 foreign companies, five U.S. federal and state government agencies and at least two non-governmental organizations. Prosecutors say the attackers stole more than 31 terabytes of academic information, research material and intellectual property, along with employee email accounts.
Authorities allege that many of the attacks were conducted on behalf of Iran’s Islamic Revolutionary Guard Corps, or IRGC, as well as other Iranian government and university clients.
The Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi. Prosecutors say the organization worked with hackers-for-hire and other contractors to break into non-Iranian scientific and research systems and obtain academic data, intellectual property, email accounts and other proprietary information.
The university campaign was particularly extensive. The defendants allegedly targeted more than 100,000 professor accounts worldwide and successfully compromised about 8,000 accounts at 144 U.S. universities and 178 universities in countries including Australia, Canada, China, Germany, Japan, the United Kingdom and others.
The campaign reportedly continued until at least December 2017. Using stolen credentials, the attackers allegedly accessed professor accounts and downloaded academic journals, theses, dissertations, electronic books and other research materials covering areas such as science, technology, engineering, social sciences and medicine. Prosecutors say at least 31.5 terabytes of academic data and intellectual property were ultimately transferred to servers outside the United States controlled by members of the conspiracy.
The stolen material was allegedly not only collected for Iranian government and university clients but also sold through websites called Megapaper and Gigapaper. According to the indictment, Megapaper sold stolen academic resources to customers in Iran, while Gigapaper offered customers access to compromised professor accounts that could be used to reach online library systems at universities in the United States and other countries.
The alleged hacking operation also extended beyond universities. Prosecutors say the defendants compromised employee email accounts at at least five U.S. federal and state government agencies, 42 U.S. companies and around 11 foreign companies based in Germany, Italy, Switzerland, Sweden and the United Kingdom. The victims also included organizations such as the U.S. Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF.
The expanded indictment adds eight defendants and describes additional attacks against private-sector organizations. One example involves HBO, where Behzad Mesri was separately charged over an intrusion that allegedly resulted in the theft of proprietary information and an attempted $6 million Bitcoin extortion. Several other defendants named in the Mabna Institute case were also allegedly involved in the HBO attack.
Prosecutors also accuse several defendants of using password-spraying attacks to gain unauthorized access to company and government systems before stealing data. The alleged activity caused victims to spend more than $20 million investigating and remediating the intrusions, according to the indictment.
The U.S. State Department’s Rewards for Justice program is offering rewards of up to $10 million for information that could help locate five of the defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz and Saber Shahbazi Ballojeh.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The charges include conspiracy to commit computer intrusions, conspiracy to commit wire fraud, unauthorized computer access, wire fraud and aggravated identity theft. Depending on the charge, the maximum potential penalties include prison sentences of up to 20 years, while aggravated identity theft charges carry mandatory two-year prison sentences.





