Gholamreza Rafatnejad and Ehsan Mohammadi established the Mabna Institute in 2013 in a small office in an apartment on North Sheikh Bahaei Street in Tehran.
The institute was ostensibly intended to connect Iranian universities and scientific and research institutions with academic resources abroad. Instead of purchasing subscriptions, however, Mabna hired hackers and contracted hackers-for-hire to compromise accounts belonging to university professors, company employees and foreign government officials selected as targets by Iranian government entities, including the Revolutionary Guards and Intelligence Ministry.
Over nearly five years, the Mabna network compromised almost 8,000 email and user accounts belonging to academics at 144 US universities and 178 universities in 22 other countries, including institutions in Europe, Canada, Australia, China, Israel, Japan, Malaysia, Turkey, South Korea, Singapore and Saudi Arabia.
Using the stolen accounts, the hackers downloaded academic papers, dissertations, electronic books and other research material. The US Justice Department estimated that at least 31.5 terabytes of data worth more than $3.4 billion were stolen from American universities.
Mabna’s operations extended beyond academia. At least five US federal and state government departments and agencies were targeted, along with 42 American private companies, 11 European companies, the United Nations and UNICEF.
Some of the stolen academic material was also sold through two websites, Megapaper.ir and Gigapaper.ir. The latter allowed Iranian customers to use compromised professors’ accounts to access the online libraries of foreign universities directly.
The principal tool was spear phishing, using emails or fake login pages tailored to a target’s university, research field or professional relationships. The network later employed password spraying, testing small numbers of commonly used passwords against large numbers of accounts in an effort to avoid triggering security alerts.
One of the network’s best-known operations was the 2017 hack of HBO.
Mesri began probing the company’s network and remote-access points in May that year. The hackers compromised employee accounts and stole material including unaired television episodes, scripts and plot summaries for unreleased episodes of Game of Thrones, cast and crew contact details, emails, financial documents and passwords for social media accounts.
Mesri initially demanded the equivalent of $5.5 million in Bitcoin and later increased the ransom demand to $6 million. When HBO did not pay, some of the stolen material was released.
Houshyar, Hashemloo, Fayyaz, Shahbazi and Kahzadian also participated in the operation alongside Mesri, according to US court documents.
The 2018 US indictment did not end the network’s activities.
Iran International’s investigation shows that after the identities of Mabna’s first nine publicly charged members were exposed, part of the operation was reorganized as Project Sonbol. Iran International sources say it operated under the direction of the Intelligence Ministry.
The team’s core was based in Karaj, although its infrastructure and associates operated elsewhere.
According to Iran International sources, three Intelligence Ministry officials involved in cyber operations — Avaz-Ali Nouranian, Mojtaba Javanbakht and Mohammad-Amin Fasihi Dastjerdi — had links to Sonbol and its members.
Mesri and Ghaleh-Kuhi held leadership roles. Fayyaz, Shahbazi and Mohammadreza Kadkhodaei received servers, target lists and intrusion assignments, while Kahzadian remained close to the network and worked with other members on cryptocurrency operations, credential theft and activities for the Intelligence Ministry.
According to Iran International sources and US State Department documents, Project Sonbol stole several terabytes of data from US technology companies, defense contractors, an energy company and an airline.
Sonbol applied techniques previously used by Mabna to a wider range of targets, including companies in the defense, energy, healthcare and financial sectors, while developing a stronger profit-seeking dimension.