Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Average Cyber Insurance Losses Increase Despite Fewer Claims

August 26, 2026

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

August 26, 2026

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects

August 26, 2026
Facebook X (Twitter) Instagram
Thursday, August 27
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks
News

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

Team-CWDBy Team-CWDAugust 26, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The US has unleashed a new round of sanctions on nearly 60 individuals and entities, including those suspected of cyber intrusions, as part of a new campaign against Iran.

Operation Economic Outcast was announced on August 24 by treasury secretary, Scott Bessent, as a way to cut the financial flows sustaining Tehran.

As part of these efforts, the US sanctioned five individuals linked to the Mabna Institute, a private hacking-for-hire enterprise believed to have launched cyber-attacks for the Iranian regime for several years.

These five were among 17 members of Mabna Institute indicted by the Department of Justice (DoJ) on August 18 for their role in cyber-espionage campaigns.

The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state government agencies, and at least two non-governmental organizations (NGOs).

Read more on the Mabna Institute: Iranian Threat Group Targets 380 Global Universities

The designations published by the Treasury’s Office of Foreign Assets Control (OFAC) listed 30 crypto addresses across Bitcoin, Ethereum, and TRON, belonging to four of the 17 defendants.

TRM Labs, a blockchain forensics company, explained in a blog post on August 24 that these addresses contain around $16.8m dating back to 2018.

Most ($15.5m) of the funds are found in 10 addresses linked to Keyvan Fayaz (aka Achilles, The Joker, and bc.monster), which suggests “he may have acted as a treasury of sorts for Mabna’s hacking-for-hire operations,” TRM Labs claimed.

Some $1.2m was linked to 15 addresses associated with Behzad Mesri.

“Addresses belonging to Behzad Mesri, the defendant separately charged with hacking HBO, show a pattern of layered transactions between his addresses, with hundreds of thousands ultimately funnelled to a deposit address at a large centralized exchange, likely to be cashed out – on-chain behavior commonly used to obfuscate source of funds,” TRM Labs continued.

More Work for Compliance Teams

Operation Economic Outcast also levies sanctions on entire sectors: digital assets, technology, gold, aviation and shipping.

“These determinations expand the categories of Iran-related conduct that may be subject to secondary sanctions, and they allow OFAC to sanction any person or entity providing services in support of five sectors of the Iranian economy,” TRM Labs warned.

“Under the new sectoral determination, any institution that processes a significant transaction for an Iranian exchange or digital assets business in turn risks its access to the US financial system.”

Cryptocurrency compliance teams will therefore need to screen out transactions from Iranian entities, to avoid being punished by the US government, the analytics firm noted.

“Additionally, compliance teams should be ready to screen for secondary sanctions risk, and flag incoming transactions from any wallets with exposure to Mabna Institute wallets,” it added.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleStopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Next Article Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
Team-CWD
  • Website

Related Posts

News

Average Cyber Insurance Losses Increase Despite Fewer Claims

August 26, 2026
News

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

August 26, 2026
News

Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects

August 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

What it takes to fool facial recognition

March 14, 2026

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.