Mabna Institute

31229963458?profile=RESIZE_400xMabna Institute is an Iran-based organization alleged by US authorities to have operated a large, coordinated credential-theft and data-exfiltration campaign since at least 2013.  Its principal targets were universities and research institutions, but the victim set also included private companies, government agencies, and international organizations.  US prosecutors allege that the activity supported the Islamic Revolutionary Guard Corps (IRGC), other Iranian government customers, and Iranian universities. The operation is notable less for exotic malware than for persistent, scalable social engineering: operators impersonated university services, harvested credentials, entered library and email systems, and removed large volumes of research, proprietary information, and intellectual property.

  1. Organizational Background and Mission - The US Department of the Treasury described Mabna Institute as an Iranian company founded in or about 2013 to help Iranian universities and scientific and research organizations obtain access to non-Iranian scientific resources.[1] US Treasury further stated that Mabna contracted with Iranian governmental and private entities to conduct hacking on their behalf. This blended model, state-directed collection combined with services for institutional customers, helped turn stolen credentials and research access into both intelligence value and commercial benefit.

The 2018 US indictment identified nine alleged leaders, contractors, associates, hackers-for-hire, and affiliates.  On 18 August 2026, the Department of Justice announced a superseding indictment charging 17 alleged members, adding eight defendants and alleging a broader victim universe.[2]  These are criminal allegations; guilt must be proven in court.

  1. Campaign Scope and Targeting - The 2026 superseding indictment alleges intrusions affecting 144 US-based universities, 178 foreign universities, at least 42 US private-sector companies, at least 11 foreign companies, at least five US federal or state agencies, and at least two non-governmental organizations. Earlier in a 2018 public filing, it was described that a closely related scope and stated that more than 31 terabytes of academic data and intellectual property were stolen, together with access to employee email accounts.[3]
  • Higher education: professors, researchers, librarians, and federated-access users with rights to subscription databases and unpublished research.
  • Government: agencies holding regulatory, energy, labor, and administrative information.
  • Private sector: employees with access to proprietary data, intellectual property, and business email.
  • International and nonprofit organizations: entities whose accounts could expose policy, humanitarian, or operational information.
  1. Tradecraft and Attack Lifecycle - Target research: operators identified academics and staff whose accounts offered access to valuable journals, repositories, email, or research systems.
  • Impersonation and spearphishing: messages and login pages were made to resemble trusted university or library services.[4]
  • Credential capture: victims were induced to enter usernames and passwords into fraudulent pages.
  • Account exploitation: stolen credentials were used to enter email, library, and institutional systems, often without deploying conspicuous malware.
  • Collection and exfiltration: operators downloaded subscription content, academic datasets, proprietary files, and mailbox contents.
  • Distribution or monetization: prosecutors allege that stolen information and account access benefited the IRGC, Iranian government customers, and Iranian universities.

This tradecraft is operationally effective because it exploits trust and legitimate functionality.  Successful access may look like a normal user session, while academic environments often have large, decentralized populations, extensive external collaboration, and valuable subscription privileges.  The principal defensive challenge is therefore identity security and anomalous-access detection rather than malware detection alone.

  1. Strategic Objectives and Impact - Mabna Institute’s alleged activity served overlapping objectives: acquiring research without paying normal access or development costs; supplying intelligence and technical knowledge to state customers; and extracting private financial value from stolen identifiers and access. The harms include loss of intellectual property, compromised personal and institutional identities, incident-response expense, legal and contractual exposure, and erosion of trust in academic collaboration. The 2018 indictment alleged that the affected US universities had spent approximately $3.4 billion to procure and access the targeted data, a measure of the information’s acquisition value, not necessarily a direct cash-loss calculation.
  2. Attribution, Indictments, and Sanctions - In March 2018, the Department of Justice unsealed charges against nine Iranian nationals for offenses including conspiracy to commit computer intrusions, wire fraud, unauthorized access for private financial gain, and aggravated identity theft.[5] The FBI published wanted notices describing the individuals as alleged Mabna leaders, contractors, associates, or affiliates and as international flight risks. In a coordinated action, the Treasury Department’s Office of Foreign Assets Control designated Mabna Institute and associated individuals under authorities addressing significant malicious cyber-enabled activity.[6]  The 2026 superseding indictment expanded the alleged network to 17 defendants and retained the central allegation that the campaign operated for the benefit of the IRGC and other Iranian entities.
  3. Defensive Priorities
  • Deploy phishing-resistant multifactor authentication for email, identity-provider, VPN, library, and privileged accounts.
  • Monitor for impossible travel, unfamiliar devices, anomalous downloads, unusual mailbox rules, and high-volume access to repositories.
  • Restrict legacy authentication and apply conditional-access controls based on device health, geography, and risk.
  • Train users to navigate directly to institutional portals instead of following login links in unsolicited messages.
  • Coordinate identity, library, research-computing, and security teams so subscription abuse and account compromise are investigated together.
  • Preserve logs for identity-provider events, email access, proxy/library systems, and bulk downloads; rehearse credential-theft response procedures.
  • Screen relevant transactions and counterparties against current sanctions requirements with qualified legal guidance.
  1. Analytic Assessment - Mabna Institute demonstrates how a state-aligned actor can generate strategic value through scalable credential theft rather than technically novel exploitation. The group’s alleged persistence, broad targeting, and concentration on legitimate information services indicate that research-intensive organizations should treat identity telemetry, library-access monitoring, and bulk-download analytics as core counterintelligence controls. Because public reporting is dominated by US indictments and sanctions announcements, assessments of intent and structure should distinguish proven facts from government allegations and remain open to revision as judicial proceedings and new technical evidence develop.

This AI created article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:

 

Weekly Cyber Intelligence Briefings:

 

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] U.S. Department of Justice, “Nine Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps” (Mar. 23, 2018), describing Mabna Institute’s creation, role, and work for the IRGC. https://www.justice.gov/usao-sdny/pr/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic

[2] U.S. Department of Justice, “17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities” (Aug. 18, 2026), announcing the superseding indictment and expanded charges. https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary

[3] U.S. Department of Justice, “Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps” (Mar. 23, 2018), detailing the campaign’s global victim scope and theft of academic data. https://www.justice.gov/usao-sdny/pr/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic

[4] Federal Bureau of Investigation, “Iranian Mabna Hackers,” summarizing the alleged spear-phishing and credential-theft methods used by the Mabna actors. https://www.fbi.gov/wanted/cyber/iranian-mabna-hackers

[5] U.S. Department of Justice, “Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps” (Mar. 23, 2018), announcing the 2018 criminal charges against nine Iranian defendants. https://www.justice.gov/usao-sdny/pr/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic

[6] U.S. Department of the Treasury, “Treasury Sanctions Iranian Cyber Actors for Malicious Cyber-Enabled Activities Targeting Hundreds of Universities” (Mar. 23, 2018), announcing sanctions against Mabna Institute and associated actors. https://home.treasury.gov/news/press-releases/sm0332

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!