Four Iranian nationals have been indicted for their alleged involvement in a malicious cyber operations campaign targeting the U.S. State and Treasury departments, defense contractors, and companies in New York. The Department of Justice unsealed the indictment in a Manhattan federal court, charging the individuals with computer fraud, wire fraud conspiracy, and other offenses.
The indictment alleges that between 2016 and April 2021, the defendants were part of a hacking organization that conducted coordinated computer intrusions. The hackers targeted over a dozen U.S. companies, as well as the U.S. Treasury and State Departments. The group used tactics such as tricking email recipients into clicking on malicious links that infected computers with malware.
One campaign resulted in over 200,000 compromised employee accounts, while another targeted about 2,000 employee accounts. The hackers also gained unauthorized access to an administrator's email account belonging to a defense contractor, allowing them to send hacking campaigns to employees of other defense contractors and a consulting firm.
The indictment details the roles of the defendants, including managing infrastructure, testing hacking tools, and creating social engineering campaigns. The defendants face charges of conspiracy to commit computer fraud, wire fraud, and aggravated identity theft, with potential prison sentences ranging from five to 20 years.
The U.S. government has designated the Iranian Organization for Electronic Warfare and Cyber Defense, where one defendant worked, as part of the Islamic Revolutionary Guard Corps, a foreign terrorist organization. The indictment underscores the ongoing efforts to counter cyber threats originating from Iran that endanger national security and economic stability.
The Department of State's Rewards for Justice program is offering up to $10 million for information leading to the identification or location of the defendants. Additionally, the Treasury Department has imposed sanctions against the indicted individuals and other cyber actors involved in the campaign.