The United States has imposed new sanctions on five alleged members of Iran-based hacking-for-hire outfit Mabna Institute, tightening financial pressure on a group accused of running years-long cyber-espionage campaigns against universities, companies and government agencies worldwide[1]. The designations, issued by the Treasury Department’s Office of Foreign Assets Control (OFAC) after a superseding indictment charged 17 Mabna operatives, block any of the individuals’ property in U.S. jurisdiction and generally bar U.S. persons from doing business with them[1].
Mabna Institute, sometimes tracked by security researchers under aliases such as Silent Librarian, Cobalt Dickens and TA407, is described in U.S. court documents as an Iran-based contractor that carried out intrusions on behalf of the Islamic Revolutionary Guard Corps (IRGC) and other Iranian customers[1]. A 2018 indictment and parallel sanctions action accused nine Mabna-linked hackers and the company itself of compromising systems at 144 U.S. universities, 176 universities in more than 20 other countries, dozens of private-sector firms, U.S. government agencies, and international organizations including the United Nations and UNICEF, stealing more than 30 terabytes of academic data and intellectual property[1]. Authorities estimated that victim universities had spent billions of dollars to license the research materials that the group subsequently downloaded and resold or provided to Iranian institutions[1].
The latest superseding indictment expands that earlier case to 17 defendants, alleging that Mabna Institute ran a coordinated campaign of spear-phishing and credential theft beginning around 2013 to harvest university and corporate logins at scale[1]. Prosecutors say the defendants conspired to commit computer intrusions and wire fraud, and in some instances aggravated identity theft, by using stolen usernames and passwords to access library portals, research repositories and corporate email accounts, then exfiltrating sensitive data for the benefit of Iranian universities, government agencies and private buyers[1]. Nine of the 17 individuals were first charged in 2018, and the new filing adds eight additional alleged Mabna operators while detailing a broader victim set and refined financial tracing of the group’s operations[1].
As part of the new sanctions package, OFAC has also listed 30 cryptocurrency addresses spanning Bitcoin, Ethereum and TRON that investigators say are controlled by four of the defendants and tied to proceeds from Mabna’s hacking-for-hire activities[1]. Blockchain analytics referenced by U.S. officials indicate those wallets have collectively received about $16.8 million since 2018, with roughly $15.5 million consolidated in 10 addresses attributed to alleged operator Keyvan Fayaz, suggesting he may have acted as a de facto treasurer for the group[1]. Around $1.2 million is linked to addresses associated with another sanctioned hacker, Behzad Mesri, who had previously been charged in a separate case involving the theft and attempted extortion of a U.S. media company[1].
Security agencies and researchers have long warned that Mabna-linked operators specialize in highly tailored phishing emails that mimic legitimate university library or IT notices to trick faculty and students into entering their credentials on cloned login pages[1]. Campaigns attributed to the group are believed to have targeted more than 300 universities across over 20 countries, including at least two dozen institutions in Australia, and to have compromised thousands of academic accounts used to pull journals, dissertations and e-books across scientific and technical disciplines[1]. Even after the initial 2018 charges, reporting from both law enforcement and threat-intelligence firms has indicated that Mabna-associated actors continued to run university-themed phishing operations under the Silent Librarian and related monikers[1].
For defenders in higher education and research-heavy enterprises, the renewed U.S. focus on Mabna Institute underscores that credential theft and library-themed phishing remain primary vectors in Iranian state-linked cyber-espionage. Universities and partners should tighten controls around access to library and research portals by enforcing multi-factor authentication, monitoring for anomalous logins from unusual geographies or anonymizing services, and running targeted awareness campaigns about spoofed library and single sign-on pages. Security teams should also review threat-intelligence feeds and government advisories for newly published indicators tied to Mabna, including sanctioned email accounts and cryptocurrency wallets, and ensure those are blocked or closely monitored in their own environments.
