Actor Profile

Iran-linked cyber actors affiliated with Iran's Ministry of Intelligence and Security (MOIS), specifically members of the Tehran-based Mabna Institute. The group conducts cyber espionage operations in support of Iran's political objectives, including targeting U.S. critical infrastructure and civilians. Notably, these actors are also motivated by personal financial gain, leading some to prioritize profit over state-directed operations, including targeting Iranian companies. Five individuals have been sanctioned and indicted: Behzad Mesri (previously sanctioned for HBO extortion), Mojtaba Ghal'eh-Kuhi, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i. Arman Kahzadian is also sanctioned for cryptocurrency theft activities.

TTPs (Tactics, Techniques, Procedures)

The MOIS-affiliated actors conduct extensive network compromise operations targeting U.S. critical infrastructure since at least late 2023. Primary TTPs include: network exploitation and data exfiltration from energy companies, defense contractors, healthcare institutions, IT companies, and financial institutions; breaches of local, state, and federal government offices (summer 2024); telecommunications company compromise and data theft (2025); cryptocurrency wallet compromise and theft (T1657 Financial Theft - over $30,000 Bitcoin stolen in summer 2023). Blockchain analysis reveals $16.8 million in total funds received across 30 wallets linked to the five Mabna Institute members, with Keyvan Fayyaz Ghareh Blagh's addresses accounting for 92% of on-chain volume ($15.5 million between January 2018 and August 2026).

Targets & Patterns

Primary targets are U.S. critical infrastructure entities across multiple sectors: energy companies, defense contractors, healthcare institutions, information technology companies, financial institutions, and government offices (local, state, and federal). The targeting pattern reflects both state-directed espionage objectives supporting Iran's political goals and financially motivated operations driven by personal enrichment. The dual motivation has led to targeting beyond U.S. entities, including Iranian telecommunications companies when profit opportunities arise. Recent campaigns (since February 2026 airstrikes) have expanded to include high-value individuals (FBI Director Kash Patel's personal email), over 30 water and wastewater utilities across at least 12 U.S. states, and U.S. allies including the U.K. (small power plant 4-day shutdown). The breadth of targeting demonstrates both strategic intelligence collection and opportunistic financial crime.

Historical Context

Behzad Mesri was previously designated by OFAC in March 2018 for HBO targeting and attempted extortion, and again in February 2019 for acting on behalf of sanctioned Net Peygard Samavat Company. The current Mabna Institute network has been conducting compromise activity since at least late 2023. Activity intensified following U.S. and Israeli airstrikes against Iran beginning February 2026, with summer 2024 breaches of government offices, 2025 Iranian telecom targeting, and recent 2026 attacks on water/wastewater utilities. TRM Labs previously disclosed (January 2026) that U.K.-based front companies Zedcex and Zedxion facilitated operational financing for IRGC, processing approximately $1 billion in funds. The current sanctions are part of Operation Economic Outcast, described as an "unprecedented, whole-of-government, economic campaign" designating nearly 60 Iran-linked entities across nuclear, missile, oil, cyber, and digital assets networks, with focus on secondary sanctions to isolate Iran financially on- and off-chain.

Defensive Recommendations

  • Implement enhanced monitoring for data exfiltration attempts from critical infrastructure networks, particularly energy, defense, healthcare, IT, and financial sectors targeted by MOIS-affiliated actors
  • Deploy blockchain analytics and cryptocurrency wallet monitoring to detect illicit fund flows, focusing on addresses associated with sanctioned Iranian cyber actors (30 known wallets with $16.8M total received)
  • Strengthen access controls and multi-factor authentication for high-value targets including government officials and critical infrastructure operators, following the FBI Director email compromise pattern
  • Monitor for network compromise indicators associated with Mabna Institute operations, including unusual data exfiltration from OT/ICS environments in water, wastewater, and energy facilities
  • Conduct financial due diligence on digital asset exchanges and front companies to avoid sanctions violations under Operation Economic Outcast secondary sanctions regime, particularly entities with Iran nexus

---

# Geopolitical Context

Geopolitical Context

The Treasury Department's "Operation Economic Outcast" represents an escalation in U.S. economic statecraft targeting Iran, combining traditional sanctions with focus on digital asset networks. The action designates nearly 60 entities across nuclear, missile, oil, and cyber domains, with particular emphasis on Ministry of Intelligence and Security (MOIS)-affiliated cyber actors responsible for critical infrastructure breaches since late 2023. The timing appears linked to ongoing U.S.-Israeli military operations against Iran beginning February 2026, which have precipitated retaliatory Iranian cyber campaigns against U.S. and allied infrastructure. The Treasury's explicit focus on secondary sanctions signals intent to compel third-party compliance globally, particularly targeting cryptocurrency exchanges and front companies that facilitate IRGC financing. The $10 million Rewards for Justice bounty underscores the elevation of cyber threats to critical infrastructure as a national security priority comparable to kinetic threats.

State Actor Alignment

The sanctions target individuals attributed to Iran's Ministry of Intelligence and Security (MOIS) and the Mabna Institute, a Tehran-based entity previously linked to state-directed cyber espionage. Five indicted individuals—Behzad Mesri, Mojtaba Ghal'eh-Kuhi, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i—are alleged to have conducted network compromises of U.S. critical infrastructure sectors including energy, defense, healthcare, IT, and finance since late 2023. The Treasury characterizes these actors as operating on behalf of MOIS while simultaneously pursuing financially motivated cybercrime, including cryptocurrency theft totaling approximately $16.8 million across 30 wallets. The designation of U.K.-based exchanges Zedcex and Zedxion, which allegedly processed $1 billion for the Islamic Revolutionary Guard Corps (IRGC), demonstrates U.S. focus on disrupting Iran's sanctions evasion infrastructure in the digital assets sector. Iranian cyber activity is assessed to have intensified following U.S.-Israeli airstrikes beginning February 2026, with attacks extending to U.K. infrastructure.

Business Impacty pro region

The sanctions framework explicitly targets secondary sanctions enforcement, compelling global financial institutions and cryptocurrency platforms to sever Iranian connections or face U.S. penalties. European allies face pressure to align with U.S. policy, as evidenced by the designation of U.K.-based crypto exchanges and reference to a suspected Iranian attack on a British power plant in July 2026. The Treasury's characterization of this as "Economic D-Day" suggests coordination with allied governments, though the extent of European participation remains unclear. For Gulf states and Asian economies maintaining trade ties with Iran, the expanded sanctions create compliance dilemmas, particularly in energy and digital finance sectors. The $10 million reward program may incentivize defections or intelligence sharing from within Iran's cyber apparatus. Iranian targeting of water utilities across 12 U.S. states and attacks on allied infrastructure indicate potential for escalatory cycles, with critical infrastructure increasingly serving as both target and leverage in U.S.-Iran strategic competition. The focus on cryptocurrency networks reflects broader Western concern about sanctions evasion via decentralized finance.

Forecast

If the U.S. sustains secondary sanctions pressure on digital asset platforms, Iranian state-linked actors are likely to accelerate development of alternative financial channels, potentially including increased reliance on China-based cryptocurrency exchanges or peer-to-peer networks beyond Western regulatory reach. Should U.S.-Israeli military operations against Iran continue or intensify, retaliatory cyber activity targeting critical infrastructure in the U.S. and allied nations is likely to persist, with water, energy, and healthcare sectors remaining priority targets based on observed patterns since February 2026. If European governments fully align with U.S. sanctions enforcement, Iran may expand cyber operations against European critical infrastructure as demonstrated by the July 2026 U.K. power plant incident. The Treasury's emphasis on individual accountability and financial rewards may produce intelligence dividends over a 6-12 month horizon if successfully penetrating MOIS-affiliated networks. However, if the dual-use nature of these actors—serving both state intelligence objectives and personal enrichment—continues, attribution and disruption efforts may face complications as operatives shift between state-directed and criminal activities. Escalation risks remain elevated absent diplomatic off-ramps, with cyber domain serving as primary arena for Iranian asymmetric response to conventional military pressure.