© Shutterstock
A 14-count superseding indictment charging 17 members of the Mabna Institute, an Iran-based company, was unsealed on Tuesday. It describes continued efforts by the Mabna Institute to target American and international institutions.
The defendants were charged with 14 different crimes and face prison sentences ranging from two years to 20 years. Nine defendants were previously charged in a seven-count indictment announced in March 2018.
The Mabna Institute was founded in approximately 2013 to assist Iranian universities and scientific and research organizations in stealing access to non-Iranian scientific resources. It employed, contracted and affiliated itself with hackers-for-hire and other contract personnel to conduct cyber intrusions to steal academic data, intellectual property, email inboxes and other proprietary data. The defendants participated in spearphishing campaigns, the act of exchanging login credentials for compromised accounts with other co-conspirators to create targeting lists, conduct computer network reconnaissance and craft phishing messages.
The Islamic Republic of Iran’s Islamic Revolutionary Guard Corps, other Iranian government entities and university clients contracted with the institute to conduct hacking activities on their behalf.
The institute coordinated cyber intrusions into computer systems of at least two non-governmental organizations, at least five U.S. federal and state government agencies, at least 11 foreign private sector companies, at least 42 U.S.-based private sector companies, 144 U.S.-based universities and 178 foreign universities. It stole more than 31 terabytes of academic data and intellectual property from the universities and hacked the email accounts of the companies, government agencies and organizations.
During the university hacking campaign, the institute targeted more than 100,000 professors’ accounts worldwide, compromising approximately 8,000 accounts. Data and login credentials were stolen on behalf of the Iranian government and also were sold on two websites. The defendants sought research and other academic data and documents. The campaign last from approximately 2013 through least December 2017, and cost U.S.-based universities more than $3.4 billion to procure and access such data and intellectual property.
The institute targeted, compromised and exfiltrated employee email accounts for U.S. federal and state government agencies and private sector companies through password spray attacks, obtaining unauthorized access to victim systems, and exfiltrating data. The attacks cost more than $20 million to investigate and remediate the intrusions.
According to the indictment, the defendants also hacked into HBO’s computer systems, stealing proprietary data. The defendants attempted to extort HBO for approximately $6 million in Bitcoin.
Click Here For The Original Source.
