Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2567+ Articles
161+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
NEWS

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

Operation Economic Outcast sanctions ~60 Iran-linked entities including MOIS-affiliated hackers who hit energy, defense, healthcare, and US government.

Dylan H.

News Desk

August 25, 2026
3 min read

The U.S. Department of the Treasury has sanctioned nearly 60 Iran-linked entities, individuals, and vessels under "Operation Economic Outcast" — a sweeping action targeting Iran's nuclear, missile, oil, and cyber networks. Among those sanctioned are hackers affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically tied to the Tehran-based Mabna Institute, who conducted intrusions against critical infrastructure targets across the United States and beyond.

Six Individuals Indicted

Six individuals connected to the cyber campaign were indicted as part of the action:

IndividualRole
Behzad MesriPreviously designated 2018/2019; involved in HBO targeting and extortion
Mojtaba Ghal'eh-KuhiNetwork intrusion operative
Keyvan Fayyaz Ghareh BlaghConducted majority of network compromise activity; controlled 10 crypto addresses receiving ~$15.5M (92% of network volume)
Saber Shahbazi BalujehPrimary network breach operator
Mohammad Reza Kadkhoda'iPrimary network breach operator
Arman KahzadianCryptocurrency theft focus; controlled wallet holding $30,000+ Bitcoin as of summer 2023

Targets Struck

The campaign targeted a broad cross-section of critical sectors:

  • Energy companies
  • Defense contractors
  • Healthcare organizations
  • IT firms
  • Financial institutions
  • U.S. local, state, and federal government offices (summer 2024)
  • An Iranian telecom company (summer 2025)

The breadth of targeting — spanning both private sector and government, domestically and abroad — reflects the MOIS mandate to collect intelligence and project disruptive capability across strategic sectors.

Financial Trail

Analysis by TRM Labs traced approximately $16.8 million received across 30 cryptocurrency wallets linked to five members of the group, with a combined residual balance of $202,662 at the time of investigation. The largest individual actor, Fayyaz Ghareh Blagh, controlled addresses accounting for 92% of identified network volume.

The cryptocurrency dimension reflects a broader trend in state-linked threat actors using digital assets for operational financing, money movement, and proceeds from extortion or data theft operations.

Rewards for Justice

The U.S. State Department's Rewards for Justice program is offering up to $10 million for information on foreign government-directed cyberattacks against U.S. critical infrastructure — a standing offer that applies to this group and others operating under similar mandates.

Context: Mabna Institute and MOIS Operations

The Mabna Institute has been a known MOIS-affiliated entity for several years, previously sanctioned and indicted in connection with large-scale academic credential theft campaigns targeting universities globally. The current action expands the scope of attributed activity to include more direct critical infrastructure intrusions and financial crime.

MOIS cyber operations have historically combined intelligence collection with disruptive capability development — a pattern that aligns with Iran's broader strategic interests in maintaining pressure on adversaries through cyber means while maintaining plausible operational distance.

Takeaways for Defenders

  • Energy, defense, and healthcare sectors remain primary targets of Iranian state-linked actors — ensure network segmentation and privileged access controls are robust in these environments
  • Supply chain and third-party risk: The Mabna Institute previously exploited third-party credentials; review access granted to contractors and vendors
  • Cryptocurrency as a threat finance indicator: Organizations with cyber insurance or financial exposure should be aware that extortion proceeds may flow through tracked wallets
  • CISA advisories: Check current CISA and FBI joint advisories for TTPs associated with MOIS-affiliated actors for detection guidance

Source: The Hacker News — US Sanctions Iran-Linked Hackers

#Nation-State#Iran#Critical Infrastructure#Sanctions#MOIS#Threat Intelligence

Related Articles

U.S. Treasury Sanctions Russian Zero-Day Broker Operation

The U.S. Treasury sanctioned Russian zero-day exploit broker Operation Zero, its founder Sergey Zelenyuk, and affiliated entities after an FBI...

5 min read

The U.S. Sanctions Nobitex Crypto Exchange Used by Ransomware

The U.S. Treasury's OFAC has sanctioned Nobitex, Iran's largest cryptocurrency exchange, for facilitating payments linked to terrorist activities and…

5 min read

Russian Spies Aggressively Targeting Western Technology as Sanctions Bite

Western intelligence officials warn that Moscow's espionage apparatus is deploying cyber spies, hackers, and recruited middlemen to steal dual-use...

6 min read
Back to all News