Nine Iranians accused of cyber-swiping 30TB+ of blueprints from unis, biz on Tehran's orders

Gang pilfered files from 320 colleges, 47 companies in 22 nations, Uncle Sam claims

The US Department of Justice and Department of the Treasury on Friday charged nine Iranians with carrying out a series of internet attacks on more than 300 universities and 47 companies in the US and abroad, as well as federal and state agencies and the United Nations.

The defendants were involved in various capacities with the Mabna Institute, a company based in Iran that, according to the Justice Department, has been coordinating cyberattacks to steal academic data and credentials on behalf of the government of Iran.

"The indictment alleges that the defendants worked on behalf of the Iranian government, specifically the Islamic Revolutionary Guard Corps," said Deputy Attorney General Rod Rosenstein in prepared remarks delivered at a press conference in Washington, D.C., on Friday.

"They hacked the computer systems of approximately 320 universities in 22 countries. One-hundred forty-four of the victims are American universities. The defendants stole research that cost the universities approximately $3.4bn to procure and maintain."

The nine defendants – Gholamreza Rafatnejad, 38; Ehsan Mohammadi, 37; Abdollah Karima, aka Vahid Karima, 39; Mostafa Sadeghi, 28; Seyed Ali Mirkarimi, 34; Mohammed Reza Sabahi, 26; Roozbeh Sabahi, 24; Abuzar Gohari Moqadam, 37; and Sajjad Tahmasebi, 30 – are all citizens and residents of Iran, which does not have an extradition agreement with the US.

As was the case with the special counsel Robert Mueller's recent indictment of 13 Russians for 2016 US election shenanigans, it's not clear whether or when the defendants will be brought before a judge.

Warning to others

Rosenstein suggested that the indictments have value even if the defendants may be out of reach. He said the indictments highlight the need for organizations to harden their cybersecurity defenses and send a message to others that the US will take steps to protect its interests.

"By bringing these criminal charges, we reinforce a norm that most of the civilized world accepts: nation-states should not steal intellectual property for the purpose of giving domestic industries a competitive advantage," said Rosenstein.

Rosenstein said the defendants are now fugitives and risk arrest and extradition if they travel to any of the more than 100 countries that do have extradition agreements with the US. He also said the Treasury Department has taken action to limit the ability of the defendants to conduct financial transactions or do business outside of Iran.

In a parallel statement, the Department of the Treasury's Office of Foreign Assets Control said it has added one Iranian entity (the Mabna Institute) and ten Iranian individuals (the nine defendants among them) to its Specially Designated Nationals List, which blocks their interest in property under US jurisdiction and prohibits US persons from doing business with them.


The charges were welcomed by officials in the UK, which was also targeted in the attacks. In a statement, Lord Tariq Ahmad, the UK's Foreign Office Minister for Cyber, said, "The focus on universities is a timely reminder that all organisations are potential targets and need to constantly strive for the best possible cyber security."

The US indictment, unsealed in a Manhattan federal court on Friday, describes a coordinated effort from 2013 through the end of 2017 involving online reconnaissance of university professors, to determine their research interests, followed by attempted spear phishing.

Spear phishing messages, according to the indictment, would appear to be from another professor inquiring about one of the target's articles and would include a link. Clicking on the link would take the victim to a confusingly similar domain to the victim's university and present a fake login page.

Terabytes swiped

With credentials stolen in this manner, the attackers were able to exfiltrate 31.5 terabytes of academic data and intellectual property.

Over 100,000 professors worldwide were targeted in this manner, about half of them in the US. The attackers succeeded in compromising an estimated 7,998 accounts, a success rate of almost 8 per cent.

The Fog of Cyberwar: Now theft and sabotage instead of just spying


In 2016, security biz Cloudmark said that among companies that conduct phishing tests on their employees, the failure rate (success rate if you're an attacker) is 16 per cent.

The indictment also describes how the defendants allegedly went after private sector companies using a technique referred to as "password spraying." They would collect names and email addresses for employees and then try lists of commonly used passwords. The indictment does not reveal how many accounts were compromised in this way.

The defendants face charges of conspiracy to commit computer intrusion, conspiracy to commit wire fraud, unauthorized access of a computer, wire fraud, and aggravated identity theft. The resulting sentence could add up to decades behind bars, if any of defendants are actually caught, tried, and found guilty. ®

Broader topics

Other stories you might like

  • How ICE became a $2.8b domestic surveillance agency
    Your US tax dollars at work

    The US Immigration and Customs Enforcement (ICE) agency has spent about $2.8 billion over the past 14 years on a massive surveillance "dragnet" that uses big data and facial-recognition technology to secretly spy on most Americans, according to a report from Georgetown Law's Center on Privacy and Technology.

    The research took two years and included "hundreds" of Freedom of Information Act requests, along with reviews of ICE's contracting and procurement records. It details how ICE surveillance spending jumped from about $71 million annually in 2008 to about $388 million per year as of 2021. The network it has purchased with this $2.8 billion means that "ICE now operates as a domestic surveillance agency" and its methods cross "legal and ethical lines," the report concludes.

    ICE did not respond to The Register's request for comment.

    Continue reading
  • Fully automated AI networks less than 5 years away, reckons Juniper CEO
    You robot kids, get off my LAN

    AI will completely automate the network within five years, Juniper CEO Rami Rahim boasted during the company’s Global Summit this week.

    “I truly believe that just as there is this need today for a self-driving automobile, the future is around a self-driving network where humans literally have to do nothing,” he said. “It's probably weird for people to hear the CEO of a networking company say that… but that's exactly what we should be wishing for.”

    Rahim believes AI-driven automation is the latest phase in computer networking’s evolution, which began with the rise of TCP/IP and the internet, was accelerated by faster and more efficient silicon, and then made manageable by advances in software.

    Continue reading
  • Pictured: Sagittarius A*, the supermassive black hole at the center of the Milky Way
    We speak to scientists involved in historic first snap – and no, this isn't the M87*

    Astronomers have captured a clear image of the gigantic supermassive black hole at the center of our galaxy for the first time.

    Sagittarius A*, or Sgr A* for short, is 27,000 light-years from Earth. Scientists knew for a while there was a mysterious object in the constellation of Sagittarius emitting strong radio waves, though it wasn't really discovered until the 1970s. Although astronomers managed to characterize some of the object's properties, experts weren't quite sure what exactly they were looking at.

    Years later, in 2020, the Nobel Prize in physics was awarded to a pair of scientists, who mathematically proved the object must be a supermassive black hole. Now, their work has been experimentally verified in the form of the first-ever snap of Sgr A*, captured by more than 300 researchers working across 80 institutions in the Event Horizon Telescope Collaboration. 

    Continue reading
  • Shopping for malware: $260 gets you a password stealer. $90 for a crypto-miner...
    We take a look at low, low subscription prices – not that we want to give anyone any ideas

    A Tor-hidden website dubbed the Eternity Project is offering a toolkit of malware, including ransomware, worms, and – coming soon – distributed denial-of-service programs, at low prices.

    According to researchers at cyber-intelligence outfit Cyble, the Eternity site's operators also have a channel on Telegram, where they provide videos detailing features and functions of the Windows malware. Once bought, it's up to the buyer how victims' computers are infected; we'll leave that to your imagination.

    The Telegram channel has about 500 subscribers, Team Cyble documented this week. Once someone decides to purchase of one or more of Eternity's malware components, they have the option to customize the final binary executable for whatever crimes they want to commit.

    Continue reading
  • Ukrainian crook jailed in US for selling thousands of stolen login credentials
    Touting info on 6,700 compromised systems will get you four years behind bars

    A Ukrainian man has been sentenced to four years in a US federal prison for selling on a dark-web marketplace stolen login credentials for more than 6,700 compromised servers.

    Glib Oleksandr Ivanov-Tolpintsev, 28, was arrested by Polish authorities in Korczowa, Poland, on October 3, 2020, and extradited to America. He pleaded guilty on February 22, and was sentenced on Thursday in a Florida federal district court. The court also ordered Ivanov-Tolpintsev, of Chernivtsi, Ukraine, to forfeit his ill-gotten gains of $82,648 from the credential theft scheme.

    The prosecution's documents [PDF] detail an unnamed, dark-web marketplace on which usernames and passwords along with personal data, including more than 330,000 dates of birth and social security numbers belonging to US residents, were bought and sold illegally.

    Continue reading

Biting the hand that feeds IT © 1998–2022