Cyberwarfare / Nation-State Attacks
,
Fraud Management & Cybercrime
Justice Department Says Iranian Firm Sold Stolen Research Inside Iran
U.S. federal prosecutors charged 17 Iranian nationals with a decade-long hacking campaign that stole more than 31 terabytes of research and intellectual property from hundreds of universities, companies and government agencies around the world.
See Also: Experts Offer Insights from Theoretical to the Realities of AI-enabled Cybercrime
A 14-count superseding indictment unsealed Tuesday in Manhattan federal court accuses members of the Tehran-based Mabna Institute of running the intrusions since at least 2013 on behalf of Iran’s Islamic Revolutionary Guard Corps and other Iranian government clients. Eight of the defendants are newly charged, while nine others were named in an indictment made public in March 2018.
Prosecutors said Mabna Institute hackers hit 144 U.S. universities, at least five federal and state agencies, 42 U.S. companies, 178 foreign universities and at least 11 foreign companies, according to the indictment.
Iranian nationals stole information and intellectual property “of untold value,” said Assistant Attorney General for National Security John Eisenberg in a statement.
Prosecutors said Gholamreza Rafatnejad and Ehsan Mohammadi established the Mabna Institute around 2013 to help Iranian universities and research organizations obtain foreign scientific resources. The company employed and contracted with hackers-for-hire and ran the university spear-phishing campaign for the IRGC – a contractor model that has continued to shape Iranian operations against U.S. targets (see: Iranian Cyber Proxies Active But Not Nation-State Hackers).
The group targeted more than 100,000 professor accounts worldwide, successfully compromising an estimated 8,000 of them across universities in 22 countries, including Australia, Canada, Germany, Israel, Japan, Saudi Arabia and the United Kingdom, prosecutors said. The university hacking campaign ran through December 2017 and pulled academic journals, dissertations and electronic books across virtually every research discipline – material that U.S. universities spent more than $3.4 billion to procure and provide access to.
Two websites – Megapaper.ir and Gigapaper.ir – marketed the material inside Iran, according to the indictment. Megapaper sold stolen academic resources to Iranian public universities and institutions, while Gigapaper sold a service that let paying customers use compromised professor accounts to log directly into the online library systems of specific U.S. and other universities.
Victims outside academia also included the U.S. Department of Labor, the Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and the United Nations Children’s Fund, prosecutors said. Foreign corporate victims were based in Germany, Italy, Sweden, Switzerland and the United Kingdom.
The indictment ties six defendants to the 2017 breach of cable channel HBO. Behzad Mesri is accused of hacking HBO’s systems, stealing proprietary data and attempting to extort the company for about $6 million in bitcoin, while prosecutors said Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh and Arman Kahzadian were directly involved alongside him.
Three defendants used password spray attacks against private sector companies and at least two government entities, prosecutors said, running up more than $20 million in victim costs to investigate and remediate the intrusions.
“The FBI’s memory is long, and time will not blunt our resolve to pursue justice,” Assistant Director Brett Leatherman of the FBI’s cyber division said in a statement. The charges include conspiracy to commit computer intrusions, conspiracy to commit wire fraud, computer fraud, wire fraud and aggravated identity theft. The wire fraud counts carry maximum sentences of 20 years. The identity theft counts carry mandatory two-year terms.
The indictment comes as security leaders continue to warn that Iranian targeting of U.S. organizations remains opportunistic and difficult to predict, with victims often selected for access rather than strategic value (see: Cyberattacks and Unpredictable Targeting Remain an Iran Risk).
Click Here For The Original Source.
