← All stories
● Covered by 1 source · 2 reportsMedium impact1 negative1 neutral

DOJ Charges 17 Iranian Nationals for Cyber Intrusions, Offers $10M Reward

🔄 Updated 41d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 17 members of Iran's Mabna Institute charged by U.S. DOJ.
  • Targeted 144 U.S. universities, 178 foreign universities, and companies.
  • Stole over 31 TB of academic data and intellectual property.
  • $10 million reward offered for information on the charged individuals.
  • Check Point Research discovered the technique.
  • The technique uses Microsoft Defender's BTR.sys driver.
  • The technique affects Windows 7 through Windows 11 25H2.
  • Jiří Vinopal presented findings at Black Hat USA 2026 and DEF CON 34.
  • A proof-of-concept tool, BTR_CLI, was published on August 20, 2026.

Cyber Intrusion Charges Against Iranian Nationals

The U.S. Department of Justice (DoJ) has announced charges against 17 individuals associated with the Mabna Institute, an Iran-based company. These individuals are accused of conducting a widespread campaign of cyber intrusions into computer systems across various sectors.

Scope of the Attacks

Since at least 2013, the Mabna Institute allegedly targeted 144 U.S.-based universities, 178 foreign universities, 42 U.S.-based private sector companies, 11 foreign private sector companies, five U.S. federal and state government agencies, and two non-governmental organizations. The campaign continued through at least December 2017.

Data Theft and Compromises

The cyber intrusions resulted in the theft of over 31 terabytes of academic data and intellectual property from universities. Additionally, email accounts of employees at private sector companies, government agencies, and NGOs were compromised. The Mabna Institute targeted over 100,000 professor accounts globally, successfully compromising approximately 8,000 of them.

Affiliation and Reward

The defendants are accused of carrying out these intrusions on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). The Mabna Institute was founded by Gholamreza Rafatnejad and Ehsan Mohammadi around 2013. The U.S. government is offering a $10 million reward for information leading to the identification or location of these individuals.

Updates

🕒 2026-08-21 · new reporting from The Hacker News
  • Check Point Research discovered the technique.
  • The technique uses Microsoft Defender's BTR.sys driver.
  • The technique affects Windows 7 through Windows 11 25H2.
  • Jiří Vinopal presented findings at Black Hat USA 2026 and DEF CON 34.
  • A proof-of-concept tool, BTR_CLI, was published on August 20, 2026.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Check Point Research discovered a technique allowing Microsoft Defender's legitimate boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems. This method, which does not exploit a software flaw, could be used to delete security software at boot, affecting Windows 7 through Windows 11 25H2. The findings highlight a potential avenue for attackers to bypass security measures by weaponizing a trusted system component.

The U.S. Department of Justice has charged 17 members of Iran's Mabna Institute for cyber intrusions targeting universities, companies, and government agencies, stealing over 31 TB of data. The campaign, active since 2013, compromised approximately 8,000 accounts, and a $10 million reward is offered for information on the individuals.