Iran’s Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictment has more methodological detail than the press coverage suggests.

News

The DOJ unsealed a 14-count superseding indictment last week (US v. Rafatnejad, S2 18 Cr. 94, SDNY) adding 8 defendants to the original 2018 case and extending the documented timeline to at least March 2022. The headline numbers (31.5 TB, 144 US universities, $3.4B in licensing value) got the coverage. The operational detail in the document itself is worth a closer look. Three-phase university attack model Phase 1: open-source reconnaissance on individual professors. Publications, research interests, co-authors, institutional network. The goal was a convincing impersonation before any contact. Phase 2: spearphishing email appearing to come from a professor at a peer institution, referencing the target’s actual recent publications and offering links to related papers. Clicking resolved to a typosquatted domain (single character off the legitimate university URL, or an alternate TLD) hosting a cloned login page for that specific institution. Credentials logged. Phase 3: using stolen credentials to log into victim accounts and exfiltrate everything accessible: journals, dissertations, monographs, raw data. In many cases, automated forwarding rules were set on the compromised account, silently copying all subsequent incoming and outgoing mail to attacker-controlled servers. Persistent access even after a password reset. Private sector targets got a different approach: password spraying against employee email lists compiled via OSINT. Lower sophistication, higher volume. Same forwarding rule technique on success. Full mailbox exfiltration. The commercial layer is what makes this operationally unusual. The stolen academic access was not only delivered to the IRGC. Two websites, Megapaper.ir and Gigapaper.ir, resold it inside Iran. Megapaper sold individual articles to Iranian public universities on invoice. Gigapaper offered subscriptions: customers received persistent access to a compromised Western professor’s library account for direct browsing. Iranian universities were confirmed paying customers. State-sponsored IP theft with a working B2B revenue model built on top of it. Two of the defendants were simultaneously FATA members (Iran’s internal cyber police) and Mabna contractors. One had also developed a website for the Supreme Leader’s office. The overlap between the domestic surveillance apparatus and foreign offensive operations is documented explicitly in the indictment. submitted by /u/Robert-Nogacki [link] [comments]Technical Information Security Content & DiscussionRead More