US Offers Up to 0 Million for Information on Alleged Iranian Hackers as Cyber Charges Resurface + Video

Listen to this Post

Featured ImageIntroduction: A Cyber Hunt That Refuses to End

Years can pass in the world of cyber warfare, but digital operations rarely disappear as quietly as the attackers who carry them out. Infrastructure changes, aliases evolve, malware is rewritten, and stolen data may circulate long after the original intrusion has faded from public attention. Yet governments can continue pursuing the people they believe were responsible.

That is the message behind a renewed U.S. effort targeting five alleged Iranian cyber operators connected to the Iran-based Mabna Institute. The U.S. State Department’s Rewards for Justice program is offering up to $10 million for information that could help locate them, following newly unsealed federal charges connected to a much broader cyber-theft campaign.

The individuals named in the announcement are Behzad Mesri, also known as “Skote Vahshat,” Keyvan Fayaz, known by aliases including “Achilles,” “The Joker,” and “http://bc.monster,” Mojtaba Galekuhi, also known as Mojtaba Ghaleh Koui, Arman Kahzadian, and Saber Shahbazi Ballojeh.

The case reaches far beyond a single network intrusion. According to U.S. prosecutors, the alleged campaign targeted universities, private companies, government agencies, and non-governmental organizations across multiple countries. More than 31 terabytes of academic data and intellectual property were allegedly stolen.

The deeper significance is even more important. This is a reminder that cyber operations can have a very long legal and geopolitical afterlife. An attacker may leave the keyboard years ago, but an indictment, an international wanted notice, financial sanctions, or a multimillion-dollar reward can continue to follow.

The Original Case: A Massive Campaign Against Universities and Organizations

The five individuals are among 17 alleged members of the Mabna Institute who were charged in connection with a large-scale cyber-theft operation.

According to the allegations outlined by U.S. authorities, the operation targeted 144 universities in the United States and another 178 universities outside the country. At least 42 U.S. companies and 11 foreign companies were also allegedly targeted.

Government institutions were not excluded. Prosecutors said the campaign also affected at least five U.S. federal and state government agencies, as well as two non-governmental organizations.

The scale of the alleged operation demonstrates why universities became such valuable targets. Academic institutions often maintain enormous collections of scientific research, engineering studies, medical research, proprietary technology, historical archives, and intellectual property.

For a cyber espionage operation, this kind of information can be extremely valuable.

Unlike a conventional criminal attack focused on immediate financial theft, cyber espionage can produce strategic benefits that continue for years. Research can potentially support industrial development, military programs, scientific advancement, or intelligence gathering.

That makes the theft of academic data fundamentally different from stealing a credit card database.

The Five Alleged Iranian Cyber Actors

The Rewards for Justice announcement identifies five individuals whose location information could qualify for a reward of up to $10 million.

Behzad Mesri, also known as “Skote Vahshat,” is among the most recognizable names associated with the case.

Keyvan Fayaz allegedly operated under several online aliases, including “Achilles,” “The Joker,” and “http://bc.monster.”

Mojtaba Galekuhi, also identified as Mojtaba Ghaleh Koui, is another alleged member connected to the broader operation.

Arman Kahzadian and Saber Shahbazi Ballojeh were also named in the reward announcement.

The use of aliases is a familiar feature of cybercrime and cyber espionage investigations. Threat actors may operate under multiple online identities, use different usernames across platforms, change infrastructure, and separate their public identity from operational accounts.

However, attribution investigations can combine digital evidence with intelligence reporting, financial information, infrastructure analysis, seized data, and information from other sources.

Over time, what initially appears to be an anonymous online identity can become connected to a real-world individual.

Why Universities Became Prime Targets

Universities are among the most attractive environments for cyber espionage.

A single institution may contain thousands of researchers, students, administrators, contractors, and external collaborators. Each account represents a possible entry point.

Universities also operate open and collaborative networks by design. Researchers must exchange information, access international databases, communicate with external partners, and frequently work across institutional boundaries.

This creates a difficult security balance.

The same openness that supports scientific research can also create opportunities for attackers.

According to the allegations in the case, spearphishing played an important role in the campaign. Attackers allegedly used deceptive communications designed to capture credentials and gain unauthorized access to university systems.

Once a valid account is compromised, an attacker may be able to move through systems while appearing, at least initially, to be a legitimate user.

That is why credential protection has become one of the most important defensive layers in modern cybersecurity.

Spearphishing: The Human Attack Surface

Technology alone cannot eliminate phishing.

Attackers do not always need to exploit an advanced zero-day vulnerability when they can convince a user to enter a password into a convincing fake login page.

A carefully designed phishing message can imitate a university portal, cloud service, research platform, IT department, or trusted colleague.

The message may contain a sense of urgency.

It may warn that an account is about to expire.

It may claim that a document requires immediate review.

It may impersonate a security administrator.

The technical complexity of the attack may be relatively simple, but the social engineering behind it can be highly effective.

This is why cybersecurity training must move beyond generic warnings telling employees and students to “be careful.”

People need to understand how modern phishing campaigns manipulate urgency, authority, curiosity, and trust.

Password Spraying and Unauthorized Access

The allegations also describe the use of password spraying and unauthorized access against private-sector and government targets.

Password spraying differs from repeatedly attacking one account with thousands of passwords.

Instead, attackers may try a small number of commonly used passwords across many different accounts.

The strategy is designed to reduce the likelihood of triggering traditional account lockout mechanisms.

For example, rather than attempting hundreds of passwords against a single user, an attacker may test a limited number of widely used password patterns against a large population of accounts.

This technique becomes especially dangerous when organizations allow weak passwords or lack multi-factor authentication.

A stolen or guessed password should no longer be enough to open the door.

Modern identity security increasingly depends on layered verification, conditional access policies, behavioral analysis, and phishing-resistant authentication methods.

More Than 31 Terabytes of Allegedly Stolen Data

The reported theft of more than 31 terabytes of academic data and intellectual property illustrates the potential scale of cyber espionage.

Thirty-one terabytes is not simply a collection of documents.

At that volume, the data could potentially include years of research, internal communications, technical files, databases, project documentation, scientific material, and proprietary information.

The long-term consequences of intellectual property theft can be difficult to calculate.

A ransomware attack may immediately reveal itself when systems are encrypted.

An espionage operation can be far quieter.

The victim may not know that information has been copied.

The attacker may not immediately publish or sell the data.

Instead, the information can remain useful long after the initial intrusion.

That makes detection particularly challenging.

Organizations are often better at detecting destructive activity than quiet data collection.

The Alleged Connection to

U.S. prosecutors have alleged that the university spearphishing campaign was conducted on behalf of Iran’s Islamic Revolutionary Guard Corps, commonly known as the IRGC.

If cyber operators are connected to state interests, the incident moves beyond conventional cybercrime.

The objective may no longer be immediate financial profit.

Instead, the operation may involve intelligence gathering, strategic competition, technology acquisition, or long-term geopolitical advantage.

This is one of the defining characteristics of modern cyber conflict.

A phishing email can be sent by an individual sitting behind a computer, but the intelligence value of the information being targeted may extend into national security.

Cyber operations have therefore become part of the broader geopolitical landscape.

Nations now use indictments, sanctions, diplomatic pressure, intelligence operations, public attribution, and financial rewards alongside traditional law enforcement methods.

The HBO Intrusion and the $6 Million Bitcoin Demand

Behzad Mesri and several of the defendants were also allegedly connected to the 2017 intrusion involving HBO.

That incident attracted significant attention after proprietary information was stolen and a demand for approximately $6 million in Bitcoin was reportedly made.

The HBO case demonstrated another important aspect of cyber operations: the same individuals or networks may allegedly move between espionage, intellectual property theft, disruptive activity, and financially motivated extortion.

Cyber threat ecosystems are not always divided into neat categories.

A threat actor may have technical skills that can be used for multiple objectives.

The same capabilities used to steal research could theoretically support surveillance, extortion, credential theft, or intelligence collection.

For investigators, this creates a larger challenge.

Understanding a threat actor requires more than identifying a piece of malware or an IP address.

It requires understanding the entire operational ecosystem.

Why the $10 Million Reward Matters

A reward of up to $10 million is not simply a symbolic announcement.

Financial incentives can generate new leads from individuals who may have direct knowledge of a target’s identity, location, associates, infrastructure, or activities.

Rewards can also create pressure inside operational networks.

Someone who believes they are protected by distance or anonymity may suddenly face the possibility that an associate, former colleague, business contact, or other individual could provide information to authorities.

The public announcement also ensures that the names remain visible.

Cyber investigations can take years.

Operators may change aliases, move locations, abandon old infrastructure, or stop participating in visible campaigns.

A reward program can keep the case active in the public and intelligence environment.

The message is clear: time does not necessarily close the investigation.

Indictments as a Tool of Cyber Deterrence

There is an important strategic element behind public indictments of alleged cyber operators.

Many defendants in international cyber cases may never immediately appear in a U.S. courtroom.

They may live outside the reach of U.S. law enforcement or in countries unlikely to extradite them.

That does not mean an indictment has no effect.

Public attribution can restrict international travel.

Financial sanctions can create additional pressure.

Exposure can disrupt operational anonymity.

Law enforcement agencies can monitor travel routes and international movements.

A future political change or border crossing could potentially create an opportunity for arrest.

In this way, cyber indictments can impose costs even when an immediate arrest is impossible.

Attribution Is No Longer a One-Time Event

One of the most interesting aspects of this case is the passage of time.

The alleged Mabna Institute operations became public years ago, yet the U.S. government continues to pursue individuals connected to the case.

This demonstrates that cyber attribution is not necessarily a one-day announcement.

Investigations can continue.

New evidence can emerge.

Additional charges can be filed.

Previously sealed information can become public.

Financial incentives can be introduced or expanded.

The digital world often creates the illusion that everything moves quickly and disappears quickly.

Law enforcement investigations operate on a different timeline.

A campaign that ended years ago may still produce legal consequences in the future.

What Undercode Say:

A Long-Term Cyber Pursuit Is Often More Powerful Than a Single Arrest

The most important message in this case is persistence.

Cyber operators often assume that time creates safety.

They believe that old infrastructure is gone, old aliases are abandoned, and investigators have moved to newer cases.

That assumption can be dangerous.

A modern cyber investigation may accumulate evidence for years.

Digital artifacts can be correlated with intelligence reporting.

Old usernames can be connected to new identities.

Financial records can create unexpected links.

Infrastructure reuse can expose operational habits.

Travel can create physical exposure.

An old indictment can suddenly become operationally relevant again.

The $10 million reward adds another layer of pressure.

It expands the investigation beyond traditional technical evidence.

Human intelligence can become just as important as malware analysis.

A former associate may know where a suspect lives.

A business relationship may reveal travel information.

An operational mistake may expose a new location.

This is why attribution should not be viewed as the end of a cyber investigation.

Public attribution can actually be the beginning of a longer pressure campaign.

The Mabna Institute case also highlights a major weakness in the global research ecosystem.

Universities hold information with enormous strategic value.

Yet many academic environments were historically designed around openness rather than adversarial security.

Attackers understand this.

They know that researchers collaborate internationally.

They know that students frequently join and leave institutions.

They know that credentials may be reused across services.

They know that a convincing phishing page can sometimes defeat expensive security infrastructure.

The answer is not to eliminate academic collaboration.

The answer is to secure it.

Universities need stronger identity controls.

Multi-factor authentication should be standard.

Phishing-resistant authentication should be prioritized for sensitive systems.

Research data should be classified according to its value.

Large-scale downloads should be monitored.

Abnormal data transfers should generate alerts.

Dormant accounts should be reviewed.

Administrative access should be tightly controlled.

Incident response teams should understand both espionage and financially motivated attacks.

The broader lesson extends far beyond universities.

Every organization possesses information that may be more valuable than it realizes.

A company may not consider itself a strategic target.

But its intellectual property may be valuable to competitors.

Its customer relationships may support further attacks.

Its infrastructure may provide access to another organization.

Its employees may possess credentials that can be reused elsewhere.

Cybersecurity therefore cannot focus only on the question, “Who would want to attack us?”

A better question is, “What could an attacker gain by compromising us?”

The alleged campaign also demonstrates why credential security remains central to modern defense.

Attackers do not always need sophisticated exploits.

A password can be the vulnerability.

A phishing page can become the exploit.

A reused credential can become the initial access vector.

A forgotten account can become a persistent backdoor.

Organizations should therefore treat identity as part of the security perimeter.

In many environments, identity has become the perimeter.

The renewed reward effort also shows how governments are adapting to the reality of international cyber operations.

Traditional policing alone cannot solve a borderless problem.

Governments increasingly combine technical attribution, criminal charges, sanctions, intelligence operations, diplomacy, and financial incentives.

This creates a distributed model of pressure.

The objective is not always an immediate arrest.

Sometimes the objective is to reduce freedom of movement.

Sometimes it is to expose an operator.

Sometimes it is to disrupt recruitment.

Sometimes it is to create uncertainty inside a threat network.

Sometimes simply making an alleged operator internationally recognizable can change the risk calculation.

The larger cyber battlefield is therefore not limited to networks and servers.

It includes courts, borders, financial systems, intelligence agencies, diplomatic relationships, and public information.

That is the real significance of this renewed $10 million reward.

The keyboard may be thousands of kilometers away.

But the consequences of a cyber operation can eventually become very physical.

Deep Analysis: Defensive Commands and Detection Strategies

Identity Auditing: Organizations Should Begin by Finding Forgotten Accounts

Linux administrators can review local user accounts with commands such as:

cut -d: -f1 /etc/passwd

Administrators can also identify accounts with unusual or unexpected login activity:

lastlog

For organizations using centralized identity systems, the same principle applies: inactive accounts should be reviewed, privileged accounts should be monitored, and unnecessary access should be removed.

Authentication Analysis: Failed Logins Can Reveal Password-Spraying Activity

On many Linux systems, authentication failures can be reviewed with:

sudo grep "Failed password" /var/log/auth.log

On systems using systemd logs, administrators can investigate SSH authentication events with:

sudo journalctl -u ssh --since "24 hours ago"

Repeated attempts across many usernames from the same infrastructure may indicate password spraying or automated credential attacks.

Network Monitoring: Large Data Transfers Deserve Investigation

Administrators can examine active network connections using:

ss -tunap

They can also inspect current processes associated with network activity:

sudo lsof -i -P -n

Large or unusual outbound transfers should be correlated with user activity, destination reputation, and the sensitivity of the data involved.

File Integrity: Detecting Unexpected Changes Can Expose Intrusions

Organizations using Linux can calculate file hashes for important files:

sha256sum /path/to/file

For broader integrity monitoring, tools such as AIDE can help establish a baseline:

sudo aide --init

Unexpected changes to authentication files, scheduled tasks, SSH configurations, or administrative scripts should receive immediate attention.

Log Hunting: Search for Suspicious Authentication Patterns

Security teams can quickly search logs for repeated authentication failures:

sudo grep -i "authentication failure" /var/log/auth.log | tail -n 100

They can also identify IP addresses associated with failed SSH attempts:

sudo grep "Failed password" /var/log/auth.log | awk '{print $(NF-3)}' | sort | uniq -c | sort -nr

This type of analysis can help defenders identify repeated attack sources, although IP addresses should never be treated as the only evidence of attribution.

Incident Response: Suspicious Systems Should Be Isolated Before Evidence Is Lost

When an intrusion is suspected, defenders should preserve evidence and investigate carefully.

Useful initial commands may include:

ps auxf
ss -plant
sudo systemctl list-units --type=service --state=running
crontab -l

These commands can help identify unusual processes, listening services, persistence mechanisms, and unexpected scheduled tasks.

The objective is not simply to remove suspicious files.

The objective is to understand how access was obtained, what data was accessed, whether persistence exists, and whether other systems were affected.

The Reward Announcement Is Consistent With an Official U.S. Cybersecurity Enforcement Case

✅ U.S. authorities have publicly identified members of the alleged Mabna Institute network in connection with a large-scale cyber-theft and credential-targeting campaign, including activity directed at universities and other organizations.

✅ The case has been associated by U.S. authorities with alleged theft of significant volumes of academic and intellectual property data and with allegations involving operations conducted on behalf of Iran’s IRGC.

❌ It would be inaccurate to assume that a public indictment or reward announcement proves every allegation through a completed criminal trial. The charges and accusations represent the position of U.S. prosecutors and investigators, while legal guilt is determined through the judicial process.

Prediction

(+1) Cyber Attribution Will Become More Persistent and More Personal

Governments will increasingly combine indictments, sanctions, intelligence collection, rewards, and public attribution to pursue alleged state-linked cyber operators.

Identity security will become an even more critical battlefield as attackers continue targeting passwords, sessions, authentication workflows, and human behavior.

Cyber espionage campaigns against universities, research institutions, technology companies, and government organizations are likely to remain difficult to eliminate because the value of intellectual property continues to grow.

Conclusion: The Digital Past Can Still Catch Up With the People Behind the Keyboard

The renewed U.S. reward of up to $10 million sends a message that extends far beyond the five alleged Iranian cyber operators named in the announcement.

Cyber operations may happen in minutes.

Investigations can take years.

Infrastructure can disappear.

Aliases can change.

Malware can be rewritten.

But evidence, intelligence, indictments, and international attention can continue accumulating long after an operation has ended.

For organizations, the lesson is equally important.

Universities, companies, government agencies, and research institutions cannot assume that only famous targets attract sophisticated attackers. Valuable data, weak identity controls, reused credentials, and poorly monitored systems can all create opportunities.

The Mabna Institute case illustrates the enduring intersection between cybersecurity, espionage, intellectual property, and geopolitics.

And the $10 million reward demonstrates a reality that every cyber operator should understand.

In the digital world, an attack may be temporary.

The consequences may not be.

▶️ Related Video (76% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube