The US Justice Department has expanded its case against the Mabna Institute hacking operation, bringing charges against eight additional Iranian nationals and revealing a broader network behind what it describes as a state-sponsored campaign to plunder academic research and intellectual property from institutions across the United States and beyond. The move brings the total number of defendants to 17.

Nine of the defendants were originally indicted in March 2018 for hacking into more than 300 universities and private companies. The latest charges flesh out the wider alleged conspiracy, drawing in individuals accused of stealing academic research, intellectual property, emails, and other proprietary information on behalf of Iran’s Islamic Revolutionary Guard Corps (IRGC), other Iranian government bodies, universities, and paying private customers.

Who is behind the Mabna Institute hacking operation?

According to The Hill, the Mabna Institute was founded by Gholamreza Rafatnejad and Ehsan Mohammadi in approximately 2013, the same period the DoJ believes the hacking operation began. The group operated as a hacking-for-hire outfit, with its alleged clients including Iranian government agencies and private customers willing to pay for stolen research and credentials.

The eight newly charged defendants are: Saeid Houshyar, Behzad Mesri (known online as “Skote Vahshat”), Manouchehr Hashemloo, Keyvan Fayaz (known as “Achilles,” “The Joker,” and “bc.monster”), Amir Barati, Saber Shahbazi Ballojeh, Arman Kahzadian, and Mojtaba Galekuhi (also spelled “Mojtaba Ghaleh Koui”).

US Attorney Jamie McDonald framed the charges in deliberately long-range terms. ‘Today’s charges, which include eight additional defendants, reveal the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions,’ McDonald stated. ‘More than eight years after making the original indictment public, these charges make clear that the passage of time will not deter us from identifying and pursuing those who target the United States from abroad.’

Scale of the alleged theft: 31.5 terabytes and $3.4 billion

The scope of what the DoJ alleges is considerable. The operation is believed to have targeted the accounts of more than 100,000 professors worldwide, successfully compromising roughly 8,000 of them. Using that access, the hackers reportedly exfiltrated 31.5 terabytes of academic data, spanning journals, theses, dissertations, ebooks, and research across numerous disciplines, valued at approximately $3.4 billion.

The reach extended across 178 universities, 144 of which are in the US, at least 53 private firms (42 of them American), two NGOs, and at least 10 US state agencies. One named victim is HBO, which was reportedly extorted for $6 million worth of Bitcoin.

All 17 defendants now face charges including conspiracy to commit computer intrusions, wire fraud, unauthorised access for financial gain, and aggravated identity theft. Maximum penalties run to up to 20 years in prison on some counts.

Rewards for Justice: up to $10 million on offer

Alongside the indictments, the State Department has activated its Rewards for Justice programme. As CyberScoop reports, the programme is offering up to $10 million for information leading to the location of four of the defendants: Behzad Mesri, Mojtaba Galekuhi, Arman Kahzadian, Keyvan Fayaz, and Saber Shahbazi Ballojeh are named in the State Department’s announcement. A Tor link has been provided to allow anonymous tip submissions, a nod to the obvious complications of gathering intelligence on individuals believed to be operating from within Iran.

The US Department of Justice has been careful to note that all defendants are presumed innocent until proven guilty in a court of law. Given that all 17 are believed to be in Iran and none are in US custody, any trial remains a distant prospect. What the charges do accomplish, concretely, is to expand the public record of who the US government holds responsible for the campaign and to complicate international travel for anyone named on the indictment. The warrants do not expire, and as McDonald’s statement made plain, neither does the DoJ’s interest in pursuing them.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version