INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Iran-linked Hackers Target Critical Infrastructure
| 2026-08-25 18:17 MEDIUM LOW STATE-SPONSORED & ESPIONAGE CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
The US Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of a whole-of-government economic campaign aimed at crippling their ability to disrupt global critical infrastructure. The sanctions target nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks, including digital assets sectors. This multi-pronged threat comprises various clusters with distinct mission, targeting, and tradecraft, as revealed by SentinelOne. The Treasury's move is part of a broader effort to disrupt Iranian financial connections worldwide, attributed to the country's Ministry of Intelligence and Security (MOIS) behind extensive compromises of US critical infrastructure entities and financially motivated cyber theft.
Technical Mitigations AI-generated
* Implement robust encryption protocols, such as AES-256 or RSA-4096, to protect sensitive data from unauthorized access.
* Conduct regular security audits and penetration testing to identify vulnerabilities in systems and networks.
* Utilize secure communication channels, like end-to-end encrypted messaging apps (e.g., Signal), for sensitive information exchange.
* Implement multi-factor authentication (MFA) with strong passwords and biometric authentication whenever possible.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
bc•••••.monster
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Economic OutcastOperation Economic Outcast
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
cryptocurrencycryptocurrency
defensedefense
educationeducation
energyenergy
governmentgovernment
maritimemaritime
technologytechnology
Incident Timeline
at least 2013
The 17 hacktivist group used malware to target at least 42 US-based private sector companies, including five US federal and state government agencies.
Click on any entity below to view its context and source!
industry
Government
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state government agencies, and at least two non-governmental organizations (NGOs).
target_region
United States
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state government agencies, and at least two non-governmental organizations (NGOs).
attribution
DoJ
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state government agencies, and at least two non-governmental organizations (NGOs).
general_metric
17 DoJ
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state government agencies, and at least two non-governmental organizations (NGOs).
general_metric
144 based universities
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state government agencies, and at least two non-governmental organizations (NGOs).
general_metric
178 foreign universities
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state government agencies, and at least two non-governmental organizations (NGOs).
victims
42 based sector companies
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state government agencies, and at least two non-governmental organizations (NGOs).
victims
11 sector companies
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state government agencies, and at least two non-governmental organizations (NGOs).
January 6, 2018
Threat actors used stolen US government personnel access to target Iranian companies.
between January 6, 2018
Keyvan Fayyaz Ghareh Blagh, a blockchain analytics firm, added 10 cryptocurrency addresses with cumulative value of $15.5 million between January 2018 and August 2026.
Click on any entity below to view its context and source!
general_metric
10 addresses
Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm added, holds 10 addresses that have received a collective 15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network's on-chain volume.
general_metric
15.5 addresses
Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm added, holds 10 addresses that have received a collective 15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network's on-chain volume.
general_metric
92 %
Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm added, holds 10 addresses that have received a collective 15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network's on-chain volume.
July 12, 2019
Threat actors used stolen US government data to target Iranian hackers.
between July 12, 2019
Threat actors used cryptocurrency transactions to transfer $1.2 million from 15 wallet addresses associated with Behzad Mesri between July 12, 2019 and August 22, 2026.
Click on any entity below to view its context and source!
general_metric
15 wallet addresses
Likewise, 15 wallet addresses associated with Behzad Mesri have received $1.2 million between July 12, 2019, and August 22, 2026.
financial
$1.2 Mesri
Likewise, 15 wallet addresses associated with Behzad Mesri have received $1.2 million between July 12, 2019, and August 22, 2026.
at least late 2023
Keyvan Fayyaz Ghareh Blagh and Saber Shahbazi Balujeh are accused of conducting network compromise activity targeting U.S. critical infrastructure sector companies, including energy, defense, healthcare, technology, and financial institutions since at least late 2023.
Click on any entity below to view its context and source!
industry
Energy
The names of the individuals are listed below -
Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i have been accused of conducting the bulk of the network compromise activity, successfully breaching and exfiltrating data from multiple U.S. critical infrastructure sector companies since at least late 2023, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions.
industry
Defense
The names of the individuals are listed below -
Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i have been accused of conducting the bulk of the network compromise activity, successfully breaching and exfiltrating data from multiple U.S. critical infrastructure sector companies since at least late 2023, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions.
industry
Healthcare
The names of the individuals are listed below -
Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i have been accused of conducting the bulk of the network compromise activity, successfully breaching and exfiltrating data from multiple U.S. critical infrastructure sector companies since at least late 2023, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions.
industry
Technology
The names of the individuals are listed below -
Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i have been accused of conducting the bulk of the network compromise activity, successfully breaching and exfiltrating data from multiple U.S. critical infrastructure sector companies since at least late 2023, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions.
summer 2023
Arman Kahzadian used a cryptocurrency wallet worth $30,000 to target Iran-linked hackers.
Click on any entity below to view its context and source!
financial
$30,000 $ worth
Arman Kahzadian, per the Treasury, has primarily focused on cryptocurrency heists, having illicitly gained control of a wallet that held more than $30,000 worth of Bitcoin in summer 2023.
summer 2024
Threat actors used hacking tools to gain unauthorized access into the networks of several U.S. government offices in summer 2024.
Click on any entity below to view its context and source!
industry
Government
"
In summer 2024, the threat actors are believed to have broken into several local, state, and federal government offices across the U.S.
February 2026
Iranian threat actors launched a multi-pronged hacking campaign against the US and Israel, targeting over 30 water and wastewater utilities in at least 12 states.
Click on any entity below to view its context and source!
source_region
Iran, Islamic Republic of
Iranian threat actors have been attributed to a series of hacking campaigns since the U.S. and Israel began conducting airstrikes against the country in February 2026, including the
breach
of the personal email account belonging to Kash Patel, the director of the Federal Bureau of Investigation (FBI), as well as
recent attacks
targeting
over 30 water and wastewater utilities
in at least 12 U.S. states.
source_region
Israel
Iranian threat actors have been attributed to a series of hacking campaigns since the U.S. and Israel began conducting airstrikes against the country in February 2026, including the
breach
of the personal email account belonging to Kash Patel, the director of the Federal Bureau of Investigation (FBI), as well as
recent attacks
targeting
over 30 water and wastewater utilities
in at least 12 U.S. states.
attribution
the Federal Bureau of Investigation (FBI
Iranian threat actors have been attributed to a series of hacking campaigns since the U.S. and Israel began conducting airstrikes against the country in February 2026, including the
breach
of the personal email account belonging to Kash Patel, the director of the Federal Bureau of Investigation (FBI), as well as
recent attacks
targeting
over 30 water and wastewater utilities
in at least 12 U.S. states.
general_metric
30 utilities
Iranian threat actors have been attributed to a series of hacking campaigns since the U.S. and Israel began conducting airstrikes against the country in February 2026, including the
breach
of the personal email account belonging to Kash Patel, the director of the Federal Bureau of Investigation (FBI), as well as
recent attacks
targeting
over 30 water and wastewater utilities
in at least 12 U.S. states.
general_metric
12 U.S. states
Iranian threat actors have been attributed to a series of hacking campaigns since the U.S. and Israel began conducting airstrikes against the country in February 2026, including the
breach
of the personal email account belonging to Kash Patel, the director of the Federal Bureau of Investigation (FBI), as well as
recent attacks
targeting
over 30 water and wastewater utilities
in at least 12 U.S. states.
organisation
SentinelOne
The "Economic D-Day" comes as SentinelOne characterized the Iran-linked activity as a multi-pronged threat comprising various clusters, each with their own distinct mission, targeting, and tradecraft.
organisation
Telegram
"
The ongoing conflict has also led to the emergence of a pro-Iran hacktivist (and
faketivist
) ecosystem, a decentralized mix of "jihadist-aligned cyber collectives, nationalist actors, and state-adjacent influence networks" that operate through Telegram channels and websites, shared target lists, DDoS-for-hire tools, and recycled breach data and leak-amplification campaigns, per DomainTools Investigations (DTI).
organisation
DTI
"
The ongoing conflict has also led to the emergence of a pro-Iran hacktivist (and
faketivist
) ecosystem, a decentralized mix of "jihadist-aligned cyber collectives, nationalist actors, and state-adjacent influence networks" that operate through Telegram channels and websites, shared target lists, DDoS-for-hire tools, and recycled breach data and leak-amplification campaigns, per DomainTools Investigations (DTI).
2026/07/26
Threat actors used Iranian hackers to target the U.K.
Click on any entity below to view its context and source!
source_region
Iran, Islamic Republic of
The cyber activities have also extended to U.S. allies such as the U.K., with suspected Iranian hackers blamed for
causing
a 4-day shut down of a small power plant following a cyber attack last month, according to
The Telegraph
.
2026/08/18
The U.S. Justice Department sanctioned five individuals linked to Iran-linked hackers in connection with widespread compromises against US entities on or after August 18, 2026.
Click on any entity below to view its context and source!
organisation
the U.S. Justice Department
Among those sanctioned are five individuals who were
indicted
by the U.S. Justice Department last week in connection with carrying out widespread compromises against U.S. entities.
August 18
The Department of Justice indicted 17 individuals, including the Mabna Institute, for their involvement in cyber-espionage campaigns targeting critical infrastructure.
Click on any entity below to view its context and source!
tactic
Espionage
These five were among 17 members of Mabna Institute indicted by the Department of Justice (DoJ) on August 18 for their role in cyber-espionage campaigns.
organisation
Mabna Institute
These five were among 17 members of Mabna Institute indicted by the Department of Justice (DoJ) on August 18 for their role in cyber-espionage campaigns.
organisation
the Department of Justice (DoJ
These five were among 17 members of Mabna Institute indicted by the Department of Justice (DoJ) on August 18 for their role in cyber-espionage campaigns.
data_breach
17 members
These five were among 17 members of Mabna Institute indicted by the Department of Justice (DoJ) on August 18 for their role in cyber-espionage campaigns.
August 20, 2026
General Document Context Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm.
Click on any entity below to view its context and source!
general_metric
10 addresses
Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm added, holds 10 addresses that have received a collective 15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network's on-chain volume.
general_metric
15.5 addresses
Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm added, holds 10 addresses that have received a collective 15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network's on-chain volume.
general_metric
92 %
Keyvan Fayyaz Ghareh Blagh, the blockchain analytics firm added, holds 10 addresses that have received a collective 15.5 million between January 6, 2018, and August 20, 2026, accounting for 92% of the network's on-chain volume.
August 22, 2026
Iran-linked hackers used Zedcex and Zedxion front companies to facilitate operational financing for the Iranian armed forces branch, with $1 billion in funds linked to IRGC processed through these exchanges.
Click on any entity below to view its context and source!
general_metric
15 wallet addresses
Likewise, 15 wallet addresses associated with Behzad Mesri have received $1.2 million between July 12, 2019, and August 22, 2026.
financial
$1.2 Mesri
Likewise, 15 wallet addresses associated with Behzad Mesri have received $1.2 million between July 12, 2019, and August 22, 2026.
financial
$1 exchanges
Earlier this January, TRM Labs
disclosed
how two U.K.-based front companies Zedcex and Zedxion have facilitated operational financing for IRGC, with the exchanges processing about $1 billion in funds linked to the Iranian armed forces branch.
financial
$202,662 addresses
The combined residual balance across all 30 addresses is $202,662.
August 24
Treasury Secretary Scott Bessent announced Operation Economic Outcast on August 24 to cut financial flows supporting Tehran, targeting entities including Treasury and TRM Labs.
Click on any entity below to view its context and source!
organisation
Treasury
Operation Economic Outcast was announced on August 24 by treasury secretary, Scott Bessent, as a way to cut the financial flows sustaining Tehran.
campaign
Operation Economic Outcast
Operation Economic Outcast was announced on August 24 by treasury secretary, Scott Bessent, as a way to cut the financial flows sustaining Tehran.
2026/08/25
The US Department of the Treasury announced sanctions on nearly 60 Iran-linked entities, individuals, and vessels across various sectors.
Click on any entity below to view its context and source!
organisation
Treasury
"The MOIS directs several networks of cyber threat actors involved in cyber espionage in support of Iran's political goals, which include harming American civilians," the Treasury said.
organisation
MOIS
"This group frequently conducts computer network exploitations on behalf, or for the benefit, of Iran's MOIS.," the Treasury said.
organisation
Operation Economic Outcast
The action, codenamed Operation Economic Outcast, aims to cut the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC) from the financial "lifelines" that support the "leading state sponsor of terror.
organisation
the Islamic Revolutionary Guard Corps
The action, codenamed Operation Economic Outcast, aims to cut the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC) from the financial "lifelines" that support the "leading state sponsor of terror.
organisation
IRGC
The action, codenamed Operation Economic Outcast, aims to cut the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC) from the financial "lifelines" that support the "leading state sponsor of terror.
organisation
the Mabna Institute
As part of these efforts, the US sanctioned five individuals linked to the Mabna Institute, a private hacking-for-hire enterprise believed to have launched cyber-attacks for the Iranian regime for several years.
organisation
OFAC
“These determinations expand the categories of Iran-related conduct that may be subject to secondary sanctions, and they allow OFAC to sanction any person or entity providing services in support of five sectors of the Iranian economy,” TRM Labs warned.
organisation
US Sanctions Mabna Institute Hackers
US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks.
financial
$16.8 members
TRM Labs'
analysis
of the 30 wallets linked to the five Mabna Institute members has found about $16.8 million in total funds received.
organisation
Iranian Threat Group
Iranian Threat Group Targets 380 Global Universities
The designations published by the Treasury’s Office of Foreign Assets Control (OFAC) listed 30 crypto addresses across Bitcoin, Ethereum, and TRON, belonging to four of the 17 defendants.
organisation
Bitcoin, Ethereum
Iranian Threat Group Targets 380 Global Universities
The designations published by the Treasury’s Office of Foreign Assets Control (OFAC) listed 30 crypto addresses across Bitcoin, Ethereum, and TRON, belonging to four of the 17 defendants.
organisation
the Treasury Scott Bessent
Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone,"
said
Secretary of the Treasury Scott Bessent.
organisation
Mabna Institute
They are alleged to be members of the Tehran-based Mabna Institute.
organisation
Mabna
Most ($15.5m) of the funds are found in 10 addresses linked to Keyvan Fayaz (aka Achilles, The Joker, and bc.monster), which suggests “he may have acted as a treasury of sorts for Mabna's hacking-for-hire operations,” TRM Labs claimed.
financial
$15.5 $ Most
Most ($15.5m) of the funds are found in 10 addresses linked to Keyvan Fayaz (aka Achilles, The Joker, and bc.monster), which suggests “he may have acted as a treasury of sorts for Mabna's hacking-for-hire operations,” TRM Labs claimed.
financial
$1.2 Mesri
Some $1.2m was linked to 15 addresses associated with Behzad Mesri.
organisation
HBO
“Addresses belonging to Behzad Mesri, the defendant separately charged with hacking HBO, show a pattern of layered transactions between his addresses, with hundreds of thousands ultimately funnelled to a deposit address at a large centralized exchange, likely to be cashed out – on-chain behavior commonly used to obfuscate source of funds,” TRM Labs continued.
Tactical Metrics
Metrics
financial
30,000
$ Worth
Click for context!
Arman Kahzadian, per the Treasury, has primarily focused on cryptocurrency heists, having illicitly gained control of a wallet that held more than $30,000 worth of Bitcoin in summer 2023.
Metrics
financial
1,200,000
Mesri
Likewise, 15 wallet addresses associated with Behzad Mesri have received $1.2 million between July 12, 2019, and August 22, 2026.
Some $1.2m was linked to 15 addresses associated with Behzad Mesri.
Metrics
financial
1,000,000,000
Exchanges
Earlier this January, TRM Labs
disclosed
how two U.K.-based front companies Zedcex and Zedxion have facilitated operational financing for IRGC, with the exchanges processing about $1 billion in funds linked to the Iranian armed forces branch.
Metrics
financial
16,800,000
Members
TRM Labs'
analysis
of the 30 wallets linked to the five Mabna Institute members has found about $16.8 million in total funds received.
Metrics
financial
202,662
Addresses
The combined residual balance across all 30 addresses is $202,662.
Metrics
victims
42
Based Sector Companies
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state govern…
Metrics
victims
11
Sector Companies
The DoJ claimed that, since at least 2013, the 17 had carried out intrusions at 144 US-based universities, 178 foreign universities, at least 42 US-based private sector companies, 11 foreign private sector companies, five US federal and state govern…
Metrics
data_breach
17
Members
These five were among 17 members of Mabna Institute indicted by the Department of Justice (DoJ) on August 18 for their role in cyber-espionage campaigns.
Metrics
financial
15,500,000
$ Most
Most ($15.5m) of the funds are found in 10 addresses linked to Keyvan Fayaz (aka Achilles, The Joker, and bc.monster), which suggests “he may have acted as a treasury of sorts for Mabna's hacking-for-hire operations,” TRM Labs claimed.
Intelligence Sources
The Hacker News
2026-08-25
Infosecurity-Magazine
2026-08-25
US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-26T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
Treasury
entity
17x
timeline
Temporal Reference
February 2026
date
7x
attribution
Attributing Entity
Ministry of Intelligence and Security
authority
7x
industry
Targeted Sector
Government
sector
3x
source region
Origin Country
Iran, Islamic Republic of
country
3x
target region
Target Country
Iran, Islamic Republic of
country
3x
tactic
Cyber Operation Type
Espionage
tactic
2x
general metric
Addresses
10
addresses
Contextual Telemetry
Context Block
19 METRICS
campaign
Campaign
Operation Economic Outcast
operation
general metric
Utilities
30
utilities
general metric
U.S. States
12
u.s. states
financial
$ Worth
30,000
$ worth
general metric
%
92
%
general metric
Wallet Addresses
15
wallet addresses
financial
Mesri
1,200,000
mesri
financial
Exchanges
1,000,000,000
exchanges
financial
Members
16,800,000
members
financial
Addresses
202,662
addresses
general metric
Individuals
60
individuals
general metric
Doj
17
doj
general metric
Based Universities
144
based universities
general metric
Foreign Universities
178
foreign universities
victims
Based Sector Companies
42
based sector companies
victims
Sector Companies
11
sector companies
data breach
Members
17
members
financial
$ Most
15,500,000
$ most
general metric
Global Universities
380
global universities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.