ctipilot.ch

Mabna Institute

actor · actor:mabna-institute

Iran-based company that, per a US Department of Justice superseding indictment unsealed 2026-08-18, has since at least 2013 run intrusions on behalf of the Islamic Revolutionary Guard Corps against 144 US and 178 foreign universities, at least 42 US and 11 foreign companies, at least five US federal and state agencies and two NGOs; DOJ names Switzerland among both the foreign-university and foreign-company victim countries. Tradecraft is spearphishing against academic staff with reuse of stolen credentials, and password spraying against corporate and government targets. Allegations untested in court.

Coverage timeline
1
first 2026-08-20 → last 2026-08-20
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
3
pinned v19.2 · see below

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-20/doj-mabna-institute-superseding-indictment-swiss-victims · ATT&CK page ↗

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-08-20/doj-mabna-institute-superseding-indictment-swiss-victims · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-20/doj-mabna-institute-superseding-indictment-swiss-victims · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-20/doj-mabna-institute-superseding-indictment-swiss-victims · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-20/doj-mabna-institute-superseding-indictment-swiss-victims · ATT&CK page ↗

Credential Access TA0006

T1110.003Brute Force: Password Spraying×1

Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.

Evidence: 2026-08-20/doj-mabna-institute-superseding-indictment-swiss-victims · ATT&CK page ↗

Story timeline

  1. 2026-08-20DOJ's superseding indictment against Iran's Mabna Institute names Switzerland twice — among the countries whose universities were compromised, and among those whose companies had employee mailboxes taken
    active-threatsEight more defendants, a password-spray campaign against government entities, and a victim list a Swiss reader is on

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (33%)
  • justice.gov1 (33%)
  • nextgov.com1 (33%)

explore in graph

Entries about Mabna Institute (1)

2026-08-20 · view entry permalink →

NOTABLENATOA2

DOJ's superseding indictment against Iran's Mabna Institute names Switzerland twice — among the countries whose universities were compromised, and among those whose companies had employee mailboxes taken

A 14-count superseding indictment unsealed on 2026-08-18 charges 17 members of the Mabna Institute, an Iran-based company that, in the Department of Justice's words, "since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs)" (U.S. Department of Justice, 2026-08-18). Nine of the seventeen were previously charged in a seven-count indictment announced in March 2018 (U.S. Department of Justice, 2026-08-18); the new filing adds eight defendants (Nextgov/FCW, 2026-08-19). The institute worked on behalf of the Islamic Revolutionary Guard Corps, and the stolen academic material was resold through operator-run websites.

For a European reader the load-bearing detail is in DOJ's own victim breakdown rather than in the headline. The department names the countries hosting the 178 compromised foreign universities — a list that runs from Australia and Canada through Germany, Ireland, Italy, the Netherlands, Norway, Poland, Spain, Sweden and Switzerland to the United Kingdom — and separately describes "at least approximately 11 foreign companies based in Germany, Italy, Switzerland, Sweden, and the United Kingdom" whose employee email accounts were compromised (U.S. Department of Justice, 2026-08-18). Swiss universities and Swiss companies are, on the government's own account, inside this campaign's victim set. The conduct is historical — the university campaign is dated from around 2013 through at least December 2017 — so this is not notice of a live intrusion; it is a state-directed collection programme against European academic and corporate research being described, with country-level specificity, in a document published this week.

The tradecraft is worth restating precisely because it is so ordinary. Against universities, DOJ describes members of the conspiracy using stolen account credentials to obtain unauthorised access to professor accounts and using that access to steal research and other academic data; one defendant's specific role was tracking the progress of spearphishing campaigns, exchanging credentials for compromised accounts with co-conspirators, building targeting lists, conducting reconnaissance and crafting phishing messages. Against companies and at least two governmental entities, the new charges name a different method: DOJ alleges three defendants "participated in the Mabana Institute's efforts to hack into private sector companies and at least two governmental entities — including through password spray attacks, obtaining unauthorized access to victim systems, and exfiltrating data — causing victims to suffer an excess of $20 million in costs to investigate and remediate the intrusions" (U.S. Department of Justice, 2026-08-18). Nextgov describes the same operating model from the outside: the institute employed or contracted hackers who ran phishing attacks, looked for vulnerable systems and traded credentials for compromised accounts (Nextgov/FCW, 2026-08-19).

178 universities located in foreign countries, including Australia, Canada, China, Denmark, Finland, Germany, Ireland, Israel, Italy, Japan, Malaysia, Netherlands, Norway, Poland, Saudi Arabia, Singapore, South Korea, Spain, Sweden, Switzerland, Turkey and the United Kingdom.

at least approximately 11 foreign companies based in Germany, Italy, Switzerland, Sweden, and the United Kingdom

U.S. Department of Justice, Office of Public Affairs 2026-08-18
incident20 Aug 05:10Zmulti-sourceOpen finding ↗