ThreatBeaconXThreatBeaconXSubscribe
CriticalAPT · 5 min read · 24 views

17 Iranians Charged in Massive Cyber Theft Campaign Targeting Universities and Organizations

The U.S. Department of Justice has charged 17 members of Iran-based Mabna Institute over an alleged years-long cyber-theft campaign conducted for the benefit of the Iranian government, including the Islamic Revolutionary Guard Corps (IRGC). The campaign allegedly targeted 144 U.S. universities, 178 foreign universities, at least 42 U.S. companies, 11 foreign companies, government agencies and NGOs, stealing approximately 31.5 TB of academic data and intellectual property and compromising about 8,000 professor email accounts.

Written by ThreatBeaconX Research Team·Published Aug 21, 2026
The U.S. Department of Justice has unsealed a superseding indictment charging 17 members of the Iran-based Mabna Institute over an alleged long-running cyber intrusion campaign targeting universities, businesses, government agencies and non-governmental organizations.
According to the indictment, the campaign operated from at least 2013 through December 2017 and was conducted for the benefit of Iranian government entities, including the Islamic Revolutionary Guard Corps (IRGC).
The defendants allegedly stole academic research, intellectual property, email accounts and other proprietary information from victims around the world.
Key HighlightsThreat group/entity: Mabna InstituteCountry of operation: IranAlleged government beneficiary: Islamic Revolutionary Guard Corps (IRGC)Defendants charged: 17U.S. universities targeted: 144Foreign universities targeted: 178U.S. private-sector companies targeted: 42+Foreign private-sector companies targeted: 11+Government agencies targeted: 5+Academic accounts targeted: 100,000+Professor accounts compromised: approximately 8,000Academic data allegedly stolen: approximately 31.5 TBCampaign period: approximately 2013–December 2017Additional victims included the U.S. Department of Labor, Federal Energy Regulatory Commission, states of Hawaii and Indiana, the United Nations and UNICEF.Mabna Institute
The DOJ alleges that Gholamreza Rafatnejad and Ehsan Mohammadi founded the Mabna Institute around 2013 to assist Iranian universities and research organizations in obtaining unauthorized access to scientific resources.
The organization allegedly employed or contracted hackers to conduct intrusions against foreign universities and organizations.
According to the indictment, Mabna Institute also conducted hacking activities for Iranian government and university clients, including spearphishing campaigns carried out on behalf of the IRGC.
University Hacking Campaign
The largest component of the operation targeted universities.
The defendants allegedly targeted more than 100,000 professor accounts worldwide and successfully compromised approximately 8,000 accounts belonging to professors at 144 U.S. universities and 178 foreign universities.
The stolen information reportedly included:
Academic journalsResearch papersThesesDissertationsElectronic booksScientific researchEngineering informationMedical researchTechnology-related researchOther intellectual property
The campaign allegedly resulted in the theft and exfiltration of approximately 31.5 TB of academic data and intellectual property to servers outside the United States.
Credential Theft and Unauthorized Access
The attackers allegedly obtained university account credentials and used them to access systems belonging to professors and researchers.
The stolen credentials provided access to academic resources and institutional systems.
The campaign therefore demonstrates the security risks associated with compromised academic accounts, particularly where accounts provide access to large repositories of research and intellectual property.
Spearphishing
Spearphishing was an important component of the university campaign.
The indictment alleges that members of the operation created targeting lists, monitored campaign progress, exchanged compromised credentials and crafted phishing messages.
This allowed the attackers to systematically target researchers and academic staff rather than conducting indiscriminate phishing.
Private-Sector and Government Targets
The operation extended beyond universities.
The indictment alleges compromises involving:
At least 42 U.S. private-sector companiesAt least 11 foreign companiesAt least five U.S. federal or state government agenciesNon-governmental organizations
Named victims include:
U.S. Department of LaborFederal Energy Regulatory CommissionState of HawaiiState of IndianaUnited NationsUNICEF
The attackers allegedly compromised employee email accounts and exfiltrated proprietary information.
Password Spray Activity
The indictment also describes password spray attacks against private-sector and governmental organizations.
Password spraying differs from conventional brute-force attacks by attempting a small number of commonly used passwords against many accounts.
This technique can help attackers avoid account-lockout thresholds while identifying accounts with weak credentials.
Organizations should therefore monitor authentication patterns across multiple accounts rather than focusing only on repeated failures against a single user.
Stolen Academic Resources Sold
The stolen academic material was allegedly not used exclusively for intelligence purposes.
According to the DOJ, defendants also operated websites including:
Megapaper.irGigapaper.ir
These services allegedly sold stolen academic resources to customers in Iran.
Gigapaper reportedly also provided customers with access to compromised university professor accounts, allowing them to access online library systems belonging to universities.
HBO Intrusion
The indictment also describes the group's involvement in the compromise of Home Box Office (HBO).
Behzad Mesri was previously charged separately over the HBO intrusion, in which attackers allegedly stole proprietary information and attempted to extort HBO for approximately $6 million in Bitcoin.
Several other individuals charged in the superseding indictment were allegedly involved in the HBO operation.
Data Exfiltration
The university campaign allegedly involved exfiltration of approximately:
31.5 TB of academic data and intellectual property
The stolen information was reportedly transferred to servers outside the United States controlled by members of the conspiracy.
Large-scale academic data theft can provide significant intelligence value because research repositories can contain commercially valuable inventions, unpublished research and sensitive scientific information.
Impact
The alleged campaign demonstrates the potential consequences of long-term credential-focused intrusion operations.
Potential impacts include:
Intellectual-property theftAcademic research theftCredential compromiseEmail-account compromiseUnauthorized access to research databasesGovernment information exposureCorporate espionageFinancial lossesFollow-on phishingIdentity theftReputational damage
The DOJ states that U.S. universities collectively spent approximately $3.4 billion to procure and access the data and intellectual property that the attackers allegedly stole.
Detection and Hunting Opportunities
Security teams should monitor for:
Password-spray activityRepeated authentication failures across many accountsSuccessful logins following password-spray attemptsSuspicious authentication from foreign infrastructureUnusual mailbox accessLarge-scale email collectionUnexpected access to research repositoriesUnusual downloads of academic documentsBulk access to cloud or library resourcesNew forwarding rulesSuspicious OAuth applicationsCredential reuseAuthentication from unfamiliar devicesUnusual account activity outside normal working hoursSuspicious phishing campaigns targeting researchersLarge outbound data transfersNewly created administrative or service accountsRecommended MitigationsEnforce phishing-resistant MFA for privileged and research accounts.Monitor authentication attempts across multiple users for password spraying.Implement account lockout and risk-based authentication controls.Monitor unusual geographic authentication patterns.Restrict access to sensitive research repositories.Apply least privilege to academic and corporate accounts.Monitor bulk downloads and unusual data access.Protect email accounts with strong authentication controls.Deploy advanced phishing detection.Monitor OAuth and third-party application permissions.Implement DLP controls for sensitive research data.Segment high-value research environments.Conduct retrospective searches for known attacker infrastructure where available.Review compromised accounts for persistence mechanisms and forwarding rules.Rotate credentials immediately following suspected compromise.Threat Assessment
The Mabna Institute campaign illustrates a long-term cyber-espionage and intellectual-property theft operation centered on credential compromise and targeted phishing.
The alleged scale—hundreds of universities, dozens of companies and government organizations, approximately 8,000 compromised professor accounts and more than 31 TB of stolen information—demonstrates the value of academic and research environments to state-sponsored cyber actors.
The operation also highlights the importance of detecting credential abuse and password spraying, even when the initial compromise occurred years earlier.
Conclusion
The Mabna Institute case demonstrates that universities and research organizations remain attractive targets for sophisticated intelligence-collection campaigns.
Organizations should combine phishing-resistant MFA, identity analytics, password-spray detection, email monitoring, research-data protection and large-scale data-exfiltration monitoring to reduce the likelihood and impact of similar campaigns.
The charges described by the DOJ are allegations, and all defendants are presumed innocent unless proven guilty beyond a reasonable doubt.

MITRE ATT&CK Mapping

T1566.002 — Phishing: Spearphishing LinkT1110.003 — Brute Force: Password SprayingT1078 — Valid AccountsT1114 — Email CollectionT1213 — Data from Information RepositoriesT1041 — Exfiltration Over C2 Channel