HomeSecurityIranian hacker extradited to the US

Iranian hacker extradited to the US

An Iranian hacker accused of working with the IRGC (Islamic Revolutionary Guard Corps) was extradited to the United States from Montenegro this week . It is an extremely rare move, as Iranian state hackers are rarely exposed to jurisdictions that have extradition treaties with the United States. The case highlights Iran’s long-running cyberespionage campaign against Western targets

Mabna Institute Iranian hacker IRGC US extradition Montenegro

According to Montenegrin authorities , the arrest took place on June 25 , following an arrest warrant issued by the FBI . The suspect, a dual citizen of Turkey and Iran , is 40 years old and goes by the initials AB . Montenegrin authorities did not disclose his full name. However, according to SecurityWeek, the US released a revised indictment in August, which charged 17 members of the Mabna Institute —based in Iran— with cyberattack activities that targeted hundreds of entities in the US and abroad. The indictment names Amir Barati as one of the members of the Mabna Institute.

The Mabna Institute is an Iranian company that, according to US authorities, acted as a front for cyber operations on behalf of the IRGC and private organizations . The company is accused of a series of widespread cyberattacks that began in 2013 and caused more than $3.4 billion in damage to organizations in the US and around the world.

See also: Amir Barati extradited to the US on cyberattack charges

Mabna Institute: The scale of cyberattacks

The targets of the attacks were numerous: 144 universities in the US and 178 abroad, 42 private companies in the US and 11 abroad, 5 US government agencies , and at least 2 NGOs. The geographical scope of the attacks spanned dozens of countries, highlighting the systematic and organized nature of the campaign.

The stolen data exceeded 31 terabytes of scientific material, including academic research, intellectual property , and employee email accounts. This material was delivered to the Iranian government and sold to Iranian universities, allowing Iran to gain access to scientific knowledge without bearing the cost of the research.

Mabna Institute and IRGC: Why the release is so rare

The Mabna Institute’s connection to the IRGC is a central element of the charge. The IRGC is Iran’s most powerful military formation and has been designated a terrorist organization by the US. The use of front companies to conduct cyber operations is a standard tactic of the Iranian regime, allowing the government to deny any involvement while reaping the benefits of cyber espionage.

The method used by the Mabna Institute was based primarily on spear-phishing attacks against university professors, researchers, and employees. The hackers sent personalized emails that mimicked legitimate communications, tricking victims into revealing their credentials. Once they gained access, they systematically extracted data from the institutions’ libraries and research repositories.

See also: DeepMind Institute: New foundation for the discussion around AGI

Iranian hackers

The extradition of Iranian state-linked hackers for trial in the US is extremely rare. Cybercriminals linked to the Iranian regime typically operate from inside Iran, diligently avoiding traveling to countries that have extradition treaties with the US. This strategy provides them with substantial immunity from prosecution.

In AB, his move to Turkey in 2021 — where he acquired Turkish citizenship and legally changed his name — proved fatal. Although Turkey does not have an extradition treaty with the United States, his move to Montenegro brought him into a jurisdiction that cooperates with American authorities. The name change and acquisition of a new citizenship indicate that the suspect was aware of the risk of arrest and was trying to conceal his identity.

It is worth noting that the US government is offering rewards of up to $10 million for information about five Iranian hackers: Mesri, Galekuhi, Kahzadian, Fayaz and Ballojeh. This program, known as Rewards for Justice, is one of the US's key tools for identifying state-sponsored cybercriminals.

See also: ATP Rare Werewolf uses legitimate software in attacks

The Mabna Institute case also highlights the importance of international cooperation in the fight against cybercrime. The cooperation between the FBI and Montenegrin authorities proved crucial in the arrest and extradition of the suspect. Similar collaborations between Western countries have led to significant arrests in recent years, although Iran, Russia and China remain safe havens for hackers who choose to remain within their borders.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

For the organizations targeted by the Mabna Institute — particularly universities and research institutions — this case is a reminder of the need for strong cybersecurity measures. Implementing multi-factor authentication (MFA), regularly training staff on phishing, monitoring suspicious network activity, and segmenting systems are key defenses against such attacks. The theft of 31 terabytes of data highlights that even non-governmental organizations, such as universities, are prime targets for state cyberespionage.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS