HackMyIP
← Back to News
2026-08-20 The Hacker News

Mabna Institute Hackers Charged: 17 Iranians Linked to 31TB Academic Data Theft

VulnerabilityAPTData Breach

This week's threat landscape illustrates how attackers exploit the very tools designed to protect systems. Check Point researchers have demonstrated a troubling technique: weaponizing Microsoft Defender's signed Boot-Time Removal driver (BTR.sys) to bypass endpoint detection and response (EDR) solutions. Security researcher Jiří Vinopal showed that because BTR.sys carries a legitimate Microsoft signature, traditional signature-based blocking cannot stop it. Attackers can exploit a golden window between system startup and user-mode initialization, effectively creating a universal kernel operation engine without resorting to the typical bring-your-own-vulnerable-driver (BYOVD) approach. Tools like BTR_CLI mimic the operational footprint of legitimate Defender remediation, making detection even harder. Defenders should verify the integrity of signed components in their environment using tools like a port scanner to identify unexpected listening services that may indicate kernel-level tampering.

In a major law enforcement action, the U.S. Department of Justice has charged 17 members of the Mabna Institute, an Iran-based cyber operation tied to the Islamic Revolutionary Guard Corps (IRGC). Founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi, the group conducted coordinated intrusions against 144 U.S. universities, 178 foreign universities, 42 U.S. private-sector companies, 11 foreign companies, five federal and state agencies, and two NGOs. The campaign compromised approximately 8,000 professor accounts out of more than 100,000 targeted globally, exfiltrating over 31 terabytes of academic data and intellectual property. Stolen credentials and research were sold through two websites to benefit the Iranian government. Researchers and academics affected by state-sponsored credential theft can verify exposure using an email breach checker to determine whether their institutional accounts appeared in known dumps.

Beyond these headline incidents, this week's Threat Intel briefing surfaced additional risks including a remote code execution flaw in Gogs 10.0 self-hosted Git services, an n8n workflow-to-RCE attack chain, and AI-assisted exploit research against the GLM-5.3 model, signaling that automated exploit generation is lowering the skill barrier for attackers. Organizations should prioritize patching internet-exposed self-hosted platforms immediately and audit any automation platforms that allow untrusted workflow definitions. Security teams investigating suspicious infrastructure connections tied to these campaigns can use a WHOIS lookup to trace domain registrations back to known threat actors and infrastructure clusters associated with Mabna-linked operations.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →