ICNA

Iranian Cyber News Agency

Iran hacker

Mabna Institute

Mabna Institute is an Iranian Advanced Persistent Threat (APT) group active since 2013, focused on the theft of research data, intellectual property, and credentials from universities, government agencies, and private sector organizations. Primarily motivated by financial gain, the group has been linked to the Islamic Revolutionary Guard Corps (IRGC) and is known for extensive phishing campaigns targeting the academic community. In 2018, nine individuals associated with Mabna Institute were indicted on charges of hacking, wire fraud, and identity theft, with their activities estimated to have resulted in $3.4 billion in intellectual property loss.


List of names used by the industry:

  • TA407
  • G0122
  • Academic Serpens
  • Yellow Nabu
  • Cobalt Dickens
  • Silent Librarian

Date founded:

Founded in 2013 by founders Gholamreza Rafatnejad and Ehsan Mohammadi. Mabna Institute is located in Tehran, Sheikh Bahaii Shomali, Koucheh Dawazdeh Metri Sevom, Plak 14, Vahed 2, Code Posti 1995873351.

Affiliation:

Iranian APT that has been linked to the Islamic Revolutionary Guard Corps (IRGC).

Previous Operations:


2013 – 2017: Extensive data theft resulting in approximately 31.5TB of data compromised, and 7,998 university accounts accessed, including 3,768 professor accounts.
• March 2018: The US Department of Justice announced that nine Iranian nationals were charged with conducting a large-scale cyber theft campaign on behalf of the IRGC. The hackers penetrated systems belonging to hundreds of universities, companies and other victims to steal research, academic and proprietary data, and intellectual property.
• August 2018: A broad campaign targeting university credentials, utilizing spoofing tactics similar to previous attacks.
• July 2019: A global phishing campaign leveraged compromised university resources, deploying library-themed phishing emails.
• June 26, 2026: Amir Barati, an Iranian-Turk citizen and allegedly member of the Silent Librarian group, was arrested in Montenegro. He was wanted by the US District Court for charges including conspiracy to commit computer fraud, hacking and identity theft.

Associated Individuals:

  • Gholamreza Rafatnejad (Rafatnejad) was a founding member of the Mabna Institute and organized the Mabna Institute hacking campaign. 
  • Ehsan Mohammadi (Mohammadi) was also a founding member of the Mabna Institute. Along with Rafatnejad,Mohammadi also helped organize Mabna’s university hacking campaign and received from others compromised account credentials belonging to university professors.
  • Seyed Ali Mirkarimi (Mirkarimi) was a hacker and Mabna Institute contractor. Mirkarimi engaged in a variety of phases of Mabna’s university hacking campaign, including the crafting and testing of malicious, spearphishing emails and organizing of stolen credentials.
  • Mostafa Sadeghi (Sadeghi) was a hacker and affiliate of the Mabna Institute. Sadeghi compromised more than 1,000 university professor accounts. Sadeghi exchanged credentials for compromised professor accounts with other Mabna-affiliated actors. Sadeghi was also involved in the operation of, and maintained a financial interest in, one of the websites selling access to the stolen university data.
  • Sajjad Tahmasebi (Tahmasebi) was a Mabna Institute contractor. He helped facilitate the spearphishing campaign targeting universities by, among other things, conducting online network surveillance of victim university computer systems and maintaining lists of credentials stolen from victim professors.
  • Abdollah Karima (Karima) was a businessman who owned and operated a company that sold, through a website, access to stolen academic materials obtained through computer intrusions.Karima contracted with the Mabna Institute to direct hackingactivities. Mabna affiliates regularly provided compromised university professor login credentials to Karima.
  • Abuzar Gohari Moqadam (Gohari Moqadam) was a professor and affiliate of the Mabna Institute. Gohari Moqadamexchanged stolen credentials for compromised accounts with Mabna Institute founders Rafatnejad and Mohammadi. 
  • Roozbeh Sabahi (Sabahi) was a contractor for the Mabna Institute. Roozbeh Sabahi assisted in the execution of the various Mabna hacking activities, including its university campaign by, among other things, organizing stolen credentials obtained by Mabna Institute hackers.
  • Mohammed Reza Sabahi (Sabahi) was a Mabna Institute contractor. Sabahi assisted in the carrying out of Mabna’sspearphishing campaign targeting universities. Among his activities, Mohammed Reza Sabahi created targeting lists of university professors and catalogued academic databases at targeted universities.

Tactics/Techniques/Tradecraft/Procedures (TTP’s):
Phishing: Highly reliant on phishing campaigns targeting university students and staff, often employing library-themed lures.
• Credential Harvesting: Specializes in stealing usernames and passwords.
• Spoofing: Utilizes compromised university email accounts and URL shortening services for more convincing phishing lures.
Infrastructure: Commonly uses free domain registration services (Freenom) to host credential phishing landing pages.
Campaign Scale: Operates with relatively low-volume, targeted campaigns (tens or hundreds of messages), focusing on specific objectives.

Sources:
• Attack.mitre.org/groups/G0122
• Home.treasury.gov/news/press-releases/sm0332
• Proofpoint.com/us/threat-insight/post/threat-actor-profile-ta407-silent-librarian
• www.justice.gov/opa/pr/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary
• Justice.gov.uk/archives/opa/pr/nine-iranians
• Turkiyetoday.com/region/montenegro-police-fbi-arrest-iran-linked-hacker-wanted-by-us-3222687
• fbi.gov/wanted/cyber/iranian-mabna-hackers

LEAVE A RESPONSE

Your email address will not be published. Required fields are marked *