Mabna Institute Case Brings Alleged University-Hacking Suspect to the United States

Amir Barati extradited from Montenegro to US over alleged Mabna Institute spearphishing campaign stealing university research for IRGC.

Mabna Institute Case Brings Alleged University-Hacking Suspect to the United States
APT

Illustrative image generated with AI

Listen to this articleAudio edition · 8 min

Amir Barati, a 40-year-old dual citizen of Iran and Turkey, has been extradited from Montenegro to the United States over allegations that he helped run a campaign targeting universities and research organizations. Prosecutors say the operation stole academic information and intellectual property on a large scale.

The case centers on alleged activity linked to Iran-based Mabna Institute and Iran’s Islamic Revolutionary Guard Corps (IRGC). The reporting describes spearphishing and the use of stolen credentials, but does not identify a particular software vulnerability, CVE, malware family or affected product.

Arrest and extradition followed an FBI warrant

Montenegrin authorities arrested Barati on June 25 after the FBI issued an arrest warrant. The year of the arrest is not specified in the reports. According to The Record, he was detained while on vacation in Kotor, a coastal municipality.

The Record identifies the suspect as Barati. SecurityWeek reports that Montenegrin authorities did not name him publicly, referring to him by the initials A.B. and giving his age as 40.

Both reports say the extradition took place “this week,” but neither provides a calendar date for the transfer. The Record also says a Montenegrin court reached a final decision to extradite him this week.

In August, the U.S. Department of Justice (DOJ) named Barati in an indictment involving 17 people associated with Mabna Institute. The year is not specified. The Record calls it a 14-count indictment; SecurityWeek describes it as a 14-count superseding indictment.

Prosecutors allege that the campaign was conducted on behalf of the IRGC. SecurityWeek says the indictment also attributed activity to the defendants on behalf of private organizations. These are allegations in the U.S. case, not findings established by the reporting.

Prosecutors describe spearphishing and credential theft

The alleged campaign used spearphishing to compromise email accounts. Prosecutors say stolen credentials were then used to access professors’ accounts and institutional resources.

The Record reports that about 8,000 professor email accounts were successfully targeted between 2013 and 2017. SecurityWeek says attacks against U.S. organizations began in 2013.

Prosecutors assign Barati several alleged roles in the operation: tracking spearphishing activity, sharing credentials for compromised accounts with co-conspirators, compiling target lists, conducting computer-network reconnaissance and composing phishing messages. The reports do not specify the software or technical platform used to carry out these activities.

The reported targets extended well beyond universities. The indictment’s figures, as reported by the two outlets, include 144 U.S. universities, 178 foreign universities, 42 U.S. companies and 11 foreign companies. The Record describes the foreign-company total as at least 11. SecurityWeek also lists five U.S. government agencies and at least two nongovernmental organizations.

Stolen academic material allegedly reached Iran

The material prosecutors say was taken included academic journals, theses, dissertations, electronic books, scientific resources, employee email accounts and other academic data and intellectual property. The Record puts the amount at at least 31 terabytes; SecurityWeek reports over 31 terabytes.

According to the DOJ account cited by The Record, documents were provided to the Iranian government and sold through two websites to universities in Iran. One of the sites allegedly enabled customers in Iran to use stolen professor accounts to access online library systems at multiple U.S. universities. SecurityWeek also reports that the information was handed to the Iranian government and sold to Iranian universities.

These accounts describe alleged uses of stolen information and credentials, rather than identifying a particular technical exploit. The reports do not provide a specific vulnerability or product version for organizations to patch.

Financial figures and charges come with different formulations

The Record says U.S. officials attributed $3.4 billion in damages to Barati’s group. SecurityWeek describes the attacks as causing more than $3.4 billion in losses. The two reports do not explain whether those figures use the same calculation.

Prosecutors reportedly said affected universities spent about $20 million investigating and remediating the breaches. This is a separate estimate of response costs, not a breakdown of the larger damages or losses figure.

The Record says the charges against Barati include an alleged conspiracy involving computer intrusions, as well as wire fraud, computer fraud and identity theft. The reporting does not provide a formal severity rating or CVSS score for the alleged activity.

SecurityWeek also reports that the U.S. government is offering rewards of up to $10 million for information about five Iranian hackers: Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh. The report does not clarify whether that amount is a combined limit or applies separately to each person.

Earlier biographical claims are attributed to Iran International

Iran International, as cited by The Record, described Barati as having a long history as a hacker in Iran and as having founded the Iran Black Hats Team and Digital Boys Underground Team. Those groups were accused of attacks against Microsoft, MIT and other institutions.

The same outlet reportedly said Iran’s Intelligence Ministry arrested Barati in 2010 and coerced him into working for the ministry for several years. The Record says that, after leaving Iran and changing his name in 2021, he became a Turkish citizen. SecurityWeek also places his move to Turkey in 2021 and says he later obtained citizenship and legally changed his first and last names. These biographical accounts are attributed to Iran International; the two reports do not independently establish them.

Public reporting offers no campaign-specific remediation

The reporting identifies spearphishing and the misuse of stolen credentials as alleged methods, but supplies no indicators of compromise, defensive mitigations or specific remediation instructions. That limitation applies to the material reported here; it does not establish that such information is unavailable elsewhere.

For universities and other organizations, the allegations point to account compromise and access to institutional resources as central concerns. The reports do not, however, identify particular accounts, domains, IP addresses, messages or technical indicators that readers could use to detect this campaign.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →