Seventeen members of an Iran-based hacking operation have been charged in a massive cyber theft campaign that prosecutors say targeted hundreds of universities and other institutions around the world, stealing more than 31 terabytes of academic data and intellectual property in attacks conducted in part on behalf of Iran’s Islamic Revolutionary Guard Corps.
A 14-count superseding indictment unsealed Tuesday in New York describes a campaign that began around 2013 and continued through at least late 2017. Prosecutors say the Mabna Institute targeted more than 100,000 professor accounts and successfully compromised roughly 8,000 of them at 144 U.S. universities and 178 universities in other countries.
Once inside the accounts, the hackers allegedly stole research papers, theses, dissertations, academic journals, and other materials. U.S. universities spent more than $3.4 billion to license and obtain the kind of research and intellectual property taken by the defendants, according to prosecutors.
Nine of the defendants were first charged in 2018. The new filing adds eight more defendants and, according to the Justice Department, reveals a broader network behind the operation.
“[A]t the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value,” Assistant Attorney General for National Security John A. Eisenberg said.
According to the indictment, Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 “to assist Iranian universities and scientific and research organizations in stealing access to non-Iranian scientific resources.” The company later contracted with a network of hackers for hire to carry out the intrusions.
The hackers allegedly used stolen credentials to access university library systems and moved the stolen academic material to servers outside the United States.
Some of the stolen information was later sold to customers inside Iran through two websites connected to one of the defendants. One site offered the stolen materials directly, while another allowed customers to use compromised professor accounts to access university library systems.
The alleged operation extended beyond universities. Members of the network also compromised employee email accounts at private companies and government offices, with victims including at least 42 U.S. companies, 11 foreign companies, five U.S. federal and state agencies, and two non-governmental organizations.
Targets included the Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations, and the United Nations Children’s Fund.
Several of the defendants were also allegedly involved in the 2017 hack of HBO, in which hackers stole proprietary data and attempted to extort the company for roughly $6 million in bitcoin. Behzad Mesri was previously charged in connection with hacking HBO systems.
In other attacks against private companies and government entities, prosecutors say some of the defendants used techniques that caused victims to rack up more than $20 million in investigation and remediation costs.
The State Department’s Rewards for Justice program is offering up to $10 million for any information leading to the location of five of the defendants.

.png)
.png)

