The U.S. Department of the Treasury has sanctioned nearly 60 Iran-linked entities, individuals, and vessels under "Operation Economic Outcast" — a sweeping action targeting Iran's nuclear, missile, oil, and cyber networks. Among those sanctioned are hackers affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically tied to the Tehran-based Mabna Institute, who conducted intrusions against critical infrastructure targets across the United States and beyond.
Six Individuals Indicted
Six individuals connected to the cyber campaign were indicted as part of the action:
| Individual | Role |
|---|---|
| Behzad Mesri | Previously designated 2018/2019; involved in HBO targeting and extortion |
| Mojtaba Ghal'eh-Kuhi | Network intrusion operative |
| Keyvan Fayyaz Ghareh Blagh | Conducted majority of network compromise activity; controlled 10 crypto addresses receiving ~$15.5M (92% of network volume) |
| Saber Shahbazi Balujeh | Primary network breach operator |
| Mohammad Reza Kadkhoda'i | Primary network breach operator |
| Arman Kahzadian | Cryptocurrency theft focus; controlled wallet holding $30,000+ Bitcoin as of summer 2023 |
Targets Struck
The campaign targeted a broad cross-section of critical sectors:
- Energy companies
- Defense contractors
- Healthcare organizations
- IT firms
- Financial institutions
- U.S. local, state, and federal government offices (summer 2024)
- An Iranian telecom company (summer 2025)
The breadth of targeting — spanning both private sector and government, domestically and abroad — reflects the MOIS mandate to collect intelligence and project disruptive capability across strategic sectors.
Financial Trail
Analysis by TRM Labs traced approximately $16.8 million received across 30 cryptocurrency wallets linked to five members of the group, with a combined residual balance of $202,662 at the time of investigation. The largest individual actor, Fayyaz Ghareh Blagh, controlled addresses accounting for 92% of identified network volume.
The cryptocurrency dimension reflects a broader trend in state-linked threat actors using digital assets for operational financing, money movement, and proceeds from extortion or data theft operations.
Rewards for Justice
The U.S. State Department's Rewards for Justice program is offering up to $10 million for information on foreign government-directed cyberattacks against U.S. critical infrastructure — a standing offer that applies to this group and others operating under similar mandates.
Context: Mabna Institute and MOIS Operations
The Mabna Institute has been a known MOIS-affiliated entity for several years, previously sanctioned and indicted in connection with large-scale academic credential theft campaigns targeting universities globally. The current action expands the scope of attributed activity to include more direct critical infrastructure intrusions and financial crime.
MOIS cyber operations have historically combined intelligence collection with disruptive capability development — a pattern that aligns with Iran's broader strategic interests in maintaining pressure on adversaries through cyber means while maintaining plausible operational distance.
Takeaways for Defenders
- Energy, defense, and healthcare sectors remain primary targets of Iranian state-linked actors — ensure network segmentation and privileged access controls are robust in these environments
- Supply chain and third-party risk: The Mabna Institute previously exploited third-party credentials; review access granted to contractors and vendors
- Cryptocurrency as a threat finance indicator: Organizations with cyber insurance or financial exposure should be aware that extortion proceeds may flow through tracked wallets
- CISA advisories: Check current CISA and FBI joint advisories for TTPs associated with MOIS-affiliated actors for detection guidance