Full Report
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime
Analysis Summary
# Threat Actor: Mabna Institute
## Attribution & Identity
* **Actor Identification:** Mabna Institute (Tehran-based).
* **Affiliation:** Affiliated with Iran's Ministry of Intelligence and Security (MOIS) and linked to the Islamic Revolutionary Guard Corps (IRGC).
* **Known Individuals:**
* Behzad Mesri (Alias: Skote Vahshat)
* Mojtaba Ghal'eh-Kuhi
* Keyvan Fayyaz Ghareh Blagh
* Saber Shahbazi Balujeh
* Mohammad Reza Kadkhoda'i
* Arman Kahzadian
* **Associated Entities:** Net Peygard Samavat Company (Sanctioned front company).
## Activity Summary
The group is involved in extensive, long-term cyber espionage and financially motivated operations. Recent activities include:
* **Operation Economic Outcast:** A whole-of-government response to the group’s 2023–2026 activities.
* **Critical Infrastructure Exploitation:** Widespread compromises of U.S. energy and defense sectors (late 2023–2026).
* **Government Breaches:** Infiltration of U.S. local, state, and federal government offices in Summer 2024.
* **Cryptocurrency Theft:** High-volume digital asset theft and laundering for personal enrichment and operational financing.
## Tactics, Techniques & Procedures
* **Computer Network Exploitation (CNE):** Widespread unauthorized access to sensitive networks for data exfiltration.
* **Extortion:** Threatening to release stolen sensitive data (e.g., the HBO hack attempt).
* **Cryptocurrency Heists:** Illicitly gaining control of digital wallets (e.g., Bitcoin).
* **Front Companies:** Utilizing entities like Zedcex and Zedxion to facilitate operational financing and money laundering.
* **Targeting Domestic Entities:** Uniquely, members have targeted Iranian companies for personal profit.
## Targeting
* **Sectors:** Energy, Defense Contractors, Healthcare, Information Technology, Financial Institutions, and Government (Local, State, Federal).
* **Geography:** Primarily the United States; secondary targeting of Iranian domestic companies.
* **Victims:** HBO (historical), U.S. critical infrastructure companies, and Iranian telecommunications firms.
## Tools & Infrastructure
* **Cryptocurrency Wallets:** At least 30 wallet addresses identified, managing approximately $16.8 million in funds.
* **Exchanges:** Zedcex and Zedxion (facilitating IRGC-linked transactions).
* **Blockchain Infrastructure:** Extensive use of Bitcoin for laundering and profit.
* **C2/Domains:** (Specific domains not detailed in the article, but associated with the sanctioned Net Peygard Samavat Company).
## Implications
The group represents a dual-threat profile: a state-sponsored espionage arm for the MOIS and a decentralized criminal enterprise. Their ability to breach critical infrastructure poses a significant risk to U.S. national security and public safety. The transition toward financially motivated cybercrime suggests that actor members are using state-honed skills for personal gain, potentially complicating attribution and increasing the frequency of attacks.
## Mitigations
* **Financial Sanctions:** Compliance with OFAC designations to sever the group's ability to move funds through global financial systems.
* **Network Hardening:** Prioritizing security for critical infrastructure (Energy/Defense) through segmented networks and robust access controls.
* **Identity Management:** Implementation of IAM automation to eliminate identity exposure paths that lead to privilege escalation.
* **Blockchain Monitoring:** Tracking associated wallet addresses (e.g., those belonging to Keyvan Fayyaz Ghareh Blagh and Behzad Mesri) to prevent the liquidation of stolen assets.