← Terug naar overzicht

The U.S. Department of the Treasury announced new sanctions against Iranian cyber actors targeting critical infrastructure. This action is described as part of an unprecedented whole-of-government economic campaign against Iran and its enablers. The objective is to sever Iran's global financial connections and cut economic lifelines sustaining the regime. The sanctions target hackers linked to breaches of critical infrastructure systems. This move reflects escalating U.S. pressure on Iranian state-sponsored cyber operations.

Technical details

Iranian cyber actors affiliated with Iran's Ministry of Intelligence and Security (MOIS), operating under the Tehran-based Mabna Institute, conducted widespread network compromises against U.S. critical infrastructure since at least late 2023. Targets included energy companies, defense contractors, healthcare institutions, IT companies, and financial institutions. In summer 2024, the group breached local, state, and federal government offices across the U.S. The group also conducted cryptocurrency theft, with Arman Kahzadian illicitly gaining control of a Bitcoin wallet holding over $30,000 in summer 2023. TRM Labs analyzed 30 wallets linked to five Mabna Institute members, finding approximately $16.8 million in total funds received. Keyvan Fayyaz Ghareh Blagh controlled 10 addresses that received a collective $15.5 million between January 6, 2018 and August 20, 2026 (92% of the network's on-chain volume). Behzad Mesri's 15 wallet addresses received $1.2 million between July 12, 2019 and August 22, 2026. The combined residual balance across all 30 addresses is $202,662. UK-based front companies Zedcex and Zedxion facilitated operational financing for the IRGC, processing approximately $1 billion in funds linked to Iranian armed forces. Iranian actors also breached the personal email account of FBI Director Kash Patel, attacked over 30 water and wastewater utilities in at least 12 U.S. states, and caused a 4-day shutdown of a small UK power plant. The broader Iran-linked threat encompasses data collection and destruction, social engineering, cloud compromise, surveillance of dissidents, and opportunistic targeting of exposed operational technology (OT) assets. A pro-Iran hacktivist ecosystem operates through Telegram channels and websites, using shared target lists, DDoS-for-hire tools, and recycled breach/leak data for asymmetric information warfare.

Mitigation steps

1. Monitor and block network traffic associated with known MOIS-linked and Mabna Institute threat actor infrastructure. 2. Screen cryptocurrency transactions against the 30 sanctioned wallet addresses linked to Mabna Institute members identified by TRM Labs. 3. Report any business dealings with sanctioned individuals (Behzad Mesri, Mojtaba Ghal'eh-Kuhi, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, Arman Kahzadian) or entities (Zedcex, Zedxion, Net Peygard Samavat Company) to OFAC. 4. Critical infrastructure operators (energy, water/wastewater, healthcare, defense, IT, financial) should review network access logs for signs of unauthorized access or exfiltration since late 2023. 5. Secure operational technology (OT) assets and remove internet-exposed PLCs and SCADA systems from public access. 6. Submit information on individuals engaging in malicious cyber activities against U.S. critical infrastructure under foreign government direction to the State Department's Rewards for Justice program (up to $10 million reward). 7. Implement multi-factor authentication and enhanced monitoring on cloud, email, and remote-management systems. 8. Monitor Telegram channels and known hacktivist platforms for shared target lists and DDoS coordination. 9. Follow OFAC compliance requirements to avoid secondary sanctions for entities continuing to do business with Iran. 10. Conduct threat hunting for indicators of MOIS-affiliated compromise, including unauthorized access to government portals, lateral movement, and data exfiltration patterns consistent with the described TTPs.

Affected products

  • Cryptocurrency wallets (Bitcoin)
  • FBI Director Kash Patel personal email account
  • Iranian telecommunications companies
  • U.K. power plant (small-scale energy generator)
  • U.S. critical infrastructure (energy companies)
  • U.S. defense contractors
  • U.S. financial institutions
  • U.S. healthcare institutions
  • U.S. information technology companies
  • U.S. local
  • Water and wastewater utilities (30+ in 12 U.S. states)
  • and federal government offices
  • state

Related threat actors

  • Arman Kahzadian
  • Behzad Mesri
  • Iran Ministry of Intelligence and Security (MOIS)
  • Islamic Revolutionary Guard Corps (IRGC)
  • Keyvan Fayyaz Ghareh Blagh
  • Mabna Institute (Tehran-based)
  • Mohammad Reza Kadkhoda'i
  • Mojtaba Ghal'eh-Kuhi
  • Pro-Iran hacktivist ecosystem (jihadist-aligned cyber collectives
  • Saber Shahbazi Balujeh
  • Zedcex (IRGC front company)
  • Zedxion (IRGC front company)
  • nationalist actors
  • state-adjacent influence networks)

IOC's

Cryptocurrency wallet addresses associated with Keyvan Fayyaz Ghareh Blagh (10 addresses, $15.5M received), Cryptocurrency wallet addresses associated with Behzad Mesri (15 addresses, $1.2M received), 30 total cryptocurrency wallet addresses linked to Mabna Institute members (~$16.8M total received, combined residual balance $202,662), Zedcex (UK-registered front company for IRGC), Zedxion (UK-registered front company for IRGC, ~$1B in stablecoin transactions), Net Peygard Samavat Company (sanctioned entity linked to Behzad Mesri)

Categories

  • Critical Infrastructure
  • Data Breach & Exfiltration
  • Identity & Access

Related links