Mabna Institute is a Tehran-based Iranian hacking-for-hire organization associated with state-sponsored cyberespionage and theft of scientific research and intellectual property. Founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi, it employed or contracted hackers to conduct intrusions for Iran’s Islamic Revolutionary Guard Corps (IRGC), other Iranian government entities, universities, and private clients. Its principal documented campaign targeted universities and research institutions worldwide from approximately 2013 through at least December 2017. U.S. authorities allege that the operation targeted more than 100,000 professor accounts, compromised approximately 8,000 accounts across 144 U.S. universities and 178 universities elsewhere, and stole more than 31 terabytes of academic data and intellectual property. Targets also included private companies, U.S. federal and state agencies, nongovernmental organizations, and international organizations, including the United Nations and UNICEF. The organization’s techniques included target-list development, network reconnaissance, spearphishing, credential theft, password spraying, and data exfiltration. Operators shared compromised credentials and used them to access email accounts, university networks, and online library systems. Stolen materials included research papers, journals, dissertations, theses, and electronic books. The operation supplied stolen information to Iranian clients and monetized both research material and access to compromised academic accounts. Members were also implicated in the 2017 HBO intrusion, involving theft of proprietary information and an attempted extortion demand of approximately $6 million in Bitcoin. Some affiliated operators have additionally been linked to Ministry of Intelligence and Security-directed intrusions and financially motivated data and cryptocurrency theft. These activities reflect a combination of government-directed intelligence collection and private enrichment. A 2026 U.S. superseding indictment expanded the Mabna Institute case to 17 alleged members; the criminal allegations do not establish convictions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
72 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Allegedly conducted an IRGC-backed campaign against universities, research institutions and companies worldwide. Between 2013 and 2017, the operation reportedly compromised roughly 8,000 professor email accounts and stole at least 31 terabytes of data. Stolen material was allegedly supplied to the Iranian government and sold to universities in Iran. Barati is accused of supporting targeting, reconnaissance, spear-phishing and credential sharing.
The article links Barati and the Mabna Institute network to an Iranian state-sponsored cyberespionage campaign conducted between 2013 and 2017. Targets included 144 US universities, 178 universities elsewhere, and US and foreign companies. Approximately 8,000 professors' email accounts were compromised and 31 terabytes of academic material stolen. The material was reportedly supplied to the Iranian government and resold to Iranian universities.
An Iran-based, state-backed hacking organization whose members allegedly conducted a multiyear campaign beginning in 2013, stealing over 31 terabytes of academic data and intellectual property and compromising 8,000 professors' email accounts worldwide. Reported victims included 322 universities, 53 private companies, five government agencies, and at least two NGOs. The attackers allegedly supplied stolen data and illicit access to the Iranian government for the benefit of the Islamic Revolutionary Guard Corps and other Iranian organizations. The article centers on the extradition of alleged member Amir Barati from Montenegro to the United States.
An Iran-based state-linked hacking operation accused of conducting intrusions against universities, private companies, government agencies, and NGOs; stealing scientific resources, academic data, intellectual property, and employee email accounts; and providing or selling stolen information to Iranian government and university entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.