ICNA

Iranian Cyber News Agency

Mojtaba Ghaleh-Kuhi

Biographical details:

Ghaleh-Kuhi is Iranian and lives in Iran. He has been associated with the IRGC-CEC, IRGC Qods Force (IRGC-QF), Ministry of Intelligence and Security (MOIS), Eeleyanet Gostar Iraniyan aka Net Peygard Samavat aka Emennet Pasargad aka Aria Sepehr Ayandehsazan and Mabna Institute.


Summary of activities within Iranian Cyber Operations:
Ghaleh-Kuhi is a malicious cyber actor sponsored by Iran’s Ministry of Intelligence and Security. He has participated in hacking and data exfiltration operations against the U.S and its allies to the benefit of the Iranian government.


Key Incidents and Attribution:
As early as 2014, Ghaleh-Kuhi worked at the front company Eeleyanet Gostar Iraniyan conducting computer network operations and social engineering to benefit the IRGC QF and the IRGC CEC. Specifically, Ghaleh-Kuhi helped develop an indigenous tool used to gather intelligence used in social engineering against IRGC targets of interest.
Following his employment with Eeleyanet Gostar Iraniyan, he was recruited to work for the Mabna Institute.
Ghaleh-Kuhi is said to have been part of a hacking campaign as part of a MOIS directed effort known as the “Senabel Project”. Under this project the malicious cyber actors stole terabytes of proprietary data from several U.S entities that was exfiltrated to online accounts. Victims include a U.S information technology firm, three U.S based defense contractors, a U.S based energy company, an airline, and several other entities.

International Recognition & Legal Actions


US Criminal Indictments and Arrest Warrants:
Ghaleh-Kuhi was indicted by the U.S Department of Justice and sanctioned (find more of sanction) by the U.S Department of the Treasury for the targeting of victim organizations through computer network exploitation and intrusion.
On the 18 August 2026, the U.S Department of Justice “Rewards for Justice” program announced that it is offering a reward of up to $10 million for information leading to the identification or location of any person who, while acing at the direction or under the control of a foreign government, participates in malicious cyber activities against U.S critical infrastructure in violation of the Computer Fraud and Abuse Act.

The U.S Department of Justice unveiled the 14-count superseding (S2) indictment charging 17 members of the Mabna Institute, including Ghaleh-Kuhi. The superseding indictment alleged that, at the behest of entities including the IRGC, these defendants hacked into universities and other research institutions worldwide, including the United States, stealing at least 31 terabytes of information and intellectual property of untold value.

Sanctions and Designations: The U.S Treasury released a press release on the 24 August 2026 announcing a fresh wave of sanctions against more than 60 officials, entities, and networks linked to Iran’s military, cyber, and oil trading activities. These sanctions included Ghaleh-Kuhi and other members of the Mabna Institute.

LEAVE A RESPONSE

Your email address will not be published. Required fields are marked *