2024-02-29 DOJ SDNY press_release 123 KB 8,782 chars

U.S. Attorney Announces Charges Against Iranian National For Multi-Year Cyber Campaign Targeting U.S. Defense Contractors And Private Sector Companies

Caption
United States v. Alireza Nasab, et al.
summary

Alireza Shafie Nasab, an Iranian citizen, is accused of participating in a multi-year cyber campaign targeting U

paragraph

Alireza Shafie Nasab, an Iranian citizen, is accused of participating in a multi-year cyber campaign targeting U.S. defense contractors and private sector companies. The alleged scheme, which occurred from 2016 to 2021, involved spearphishing and social engineering tactics to infect over 200,000 victim devices, compromising sensitive or classified defense information. Nasab is charged with conspiracy to commit computer fraud, conspiracy to commit wire fraud, wire fraud, and aggravated identity theft, carrying a maximum sentence of 47 years in prison. A $10 million reward is being offered for information leading to his identification or location.

narrative

Alireza Shafie Nasab, an Iranian citizen, is accused of participating in a multi-year cyber campaign targeting U.S. defense contractors and private sector companies. The alleged scheme, which occurred from 2016 to 2021, involved spearphishing and social engineering tactics to infect over 200,000 victim devices, compromising sensitive or classified defense information. Nasab is charged with conspiracy to commit computer fraud, conspiracy to commit wire fraud, wire fraud, and aggravated identity theft, carrying a maximum sentence of 47 years in prison. A $10 million reward is being offered for information leading to his identification or location. Iranian national Alireza Shafie Nasab, employed by the Tehran-based firm Mahak Rayan Afraz—a front for state-linked cyber operations—is charged with orchestrating a multi-year cyber campaign targeting U.S. government agencies (including Treasury and State Departments), defense contractors, and New York-based companies from 2016 to 2021. Using spearphishing, social engineering, and malware, his group compromised over 200,000 employee accounts across more than a dozen victims, including by hijacking administrator credentials to launch further attacks. Nasab is accused of using stolen identities to register infrastructure and was involved in procuring tools to facilitate the cyber intrusions. He faces charges of conspiracy to commit computer fraud, conspiracy to commit wire fraud, wire fraud, and aggravated identity theft, carrying a potential maximum sentence of 47 years, plus a mandatory two-year consecutive term for identity theft. The U.S. Department of State is offering up to $10 million for information leading to his capture, as he remains at large. Iranian national Alireza Shafie Nasab is charged in a Manhattan federal indictment with orchestrating a multi-year cyber campaign from 2016 to 2021, using spearphishing, social engineering, and malware to compromise over 200,000 devices across U.S. government agencies—including the Treasury and State Departments—and defense contractors, as well as New York-based firms. Nasab, employed by the Iranian cybersecurity front company Mahak Rayan Afraz, allegedly procured infrastructure and used stolen identities to facilitate attacks, including compromising administrator accounts to launch further phishing campaigns. He faces charges of conspiracy to commit computer fraud and wire fraud, wire fraud, and aggravated identity theft, carrying a maximum potential sentence of 47 years, including a mandatory two-year consecutive term for identity theft. The U.S. Department of State is offering up to $10 million for information leading to his capture, as he remains at large in Iran. The charges are part of a broader U.S. effort to disrupt Iran’s state-tolerated cybercriminal ecosystem targeting national security and critical infrastructure.

Enriched metadata

Scheme
cyber-fraud (100%)
Court
Southern District of New York
Outcome
charged
Victims
200,000
Classified cyber-fraud(confidence 100%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Statutes
15 U.S.C. § 78j(b)17 C.F.R. § 240.10b-5
Parties
alireza nasabalireza shafie nasabfbi cyber divisionu.s. attorney's office, southern district of new york
Keywords
cybernasabdefensenational securitydefense contractorsprivate sectornationalwhichnewcampaignfbiprivatecompaniescyber campaignassistant director

Exhibits & Attached Documents (1)

Extracted insights

Dollar amounts 1
  • $10.00M $10 million $10M–$100M
Entities 4
  • person alireza nasab
  • person alireza shafie nasab
  • agency fbi cyber division
  • agency u.s. attorney's office, southern district of new york
Triples 7
  • U.S. Attorney Announces Charges Iranian National For Multi-Year Cyber Campaign Targeting U.S. Defense Contractors And Private Sector Companies
  • Defendant Participated in Cyberattacks While Employed by Iranian Company That Purported to Provide Cybersecurity Services
  • U.S. Attorney's Office, Southern District of New York Announced the unsealing of an Indictment charging Iranian citizen and resident ALIREZA SHAFIE NASAB for his involvement in a cyber-enabled campaign to compromise U.S. government and private entities
  • Alireza Shafie Nasab Participated in a cyber campaign using spearphishing and other hacking techniques to infect more than 200,000 victim devices
  • Alireza Shafie Nasab Allegedly Participated in a persistent campaign to compromise U.S. private sector and government computer systems
  • FBI Cyber Division Leverage all of our capabilities in combatting the threat waged by Iranian hacker organizations against America’s public and private sector
  • Alireza Nasab Allegedly Participated in an aggressive campaign of cyberattacks targeting U.S. government agencies, defense contractors, and New York-based companies working closely with the Department of Defense
Text layers
Extracted body text (8,782c)
Press Release U.S. Attorney Announces Charges Against Iranian National For Multi-Year Cyber Campaign Targeting U.S. Defense Contractors And Private Sector Companies Thursday, February 29, 2024 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Defendant Participated in Cyberattacks While Employed by Iranian Company That Purported to Provide Cybersecurity Services Damian Williams, the United States Attorney for the Southern District of New York; Matthew G. Olsen, the Assistant Attorney General for National Security; Bryan Vorndran, the Assistant Director of the Cyber Division of the Federal Bureau of Investigation (“FBI”); and James Smith, the Assistant Director in Charge of the New York Field Office of the FBI, announced today the unsealing of an Indictment charging Iranian citizen and resident ALIREZA SHAFIE NASAB for his involvement in a cyber-enabled campaign to compromise U.S. government and private entities, including the U.S. Departments of the Treasury and State, defense contractors, and two New York-based companies. The case has been assigned to U.S. District Judge Mary Kay Vyskocil. NASAB remains at large. U.S. Attorney Damian Williams said: “As alleged, Alireza Shafie Nasab participated in a cyber campaign using spearphishing and other hacking techniques to infect more than 200,000 victim devices, many of which contained sensitive or classified defense information. Cyber intrusion schemes such as the one alleged threaten our national security, and I’m proud of our law enforcement partners and the career prosecutors of this Office for using innovative technologies and investigative measures to disrupt and track down these cybercriminals.” Assistant Attorney General for National Security Matthew G. Olsen said: “While purporting to work as a cybersecurity specialist for Iran-based clients, Mr. Nasab allegedly participated in a persistent campaign to compromise U.S. private sector and government computer systems. Today’s charges highlight Iran’s corrupt cyber ecosystem, in which criminals are given free rein to target computer systems abroad and threaten U.S. sensitive information and critical infrastructure. Our National Security Cyber Section remains focused on disputing these cross-border hacking schemes and holding those responsible to account.” FBI Cyber Division Assistant Director Bryan Vorndran said: “The FBI will leverage all of our capabilities in combatting the threat waged by Iranian hacker organizations against America’s public and private sector. We encourage everyone to practice proper cyber hygiene to mitigate the risk of becoming vulnerable to malicious actors like Nasab. The close collaboration with partners that led to today’s unsealed indictment does not end there, and we are looking forward to continued teamwork in this space.” FBI New York Assistant Director in Charge James Smith said: “Hostile cybercriminals are determined to use hacking campaigns to harm public safety and threaten our national security. Alireza Nasab, over an extended number of years, allegedly participated in an aggressive campaign of cyberattacks targeting U.S. government agencies, defense contractors, and New York-based companies working closely with the Department of Defense. This case is a reminder that we all need to maintain proper cybersecurity and awareness to avoid falling victim to malicious cyber actors. The FBI will continue to lead the fight against hostile nation state actors attempting to harm our country in cyberspace.” According to the allegations contained in the Indictment unsealed today in Manhattan federal court:[1] From at least in or about 2016 through at least in or about April 2021, ALIREZA SHAFIE NASAB and other conspirators were members of a hacking organization that participated in a coordinated multi-year campaign to conduct and attempt to conduct computer intrusions. These intrusions targeted more than a dozen U.S. companies and the U.S. Departments of the Treasury and State. The hacking group’s private sector victims were primarily cleared defense contractors, which are companies that support U.S. Department of Defense programs. In addition, the group targeted a New York-based accounting firm and a New York-based hospitality company. In conducting their hacking campaigns, the group used spearphishing — that is, tricking an email recipient into clicking on a malicious link — to infect victim computers with malware. In the course of their campaigns against one victim, the group compromised more than 200,000 employee accounts. At another victim, the conspirators targeted 2,000 employee accounts. In order to manage their spearphishing campaigns, the group created and used a particular computer application, which enabled the conspirators to organize and deploy their spearphishing attacks. In the course of these spearphishing attacks, the conspirators compromised an administrator email account belonging to a defense contractor (“Defense Contractor-1”). Access to this administrator account empowered the conspirators to create unauthorized Defense Contractor-1 accounts, which the conspirators then used to send spearphishing campaigns to employees of a different defense contractor and a consulting firm. In addition to spearphishing, the conspirators utilized social engineering, which involved impersonating others, generally women, in order to obtain the confidence of victims. These social engineering contacts were another means the conspiracy used to deploy malware onto victim computers and compromise those devices and accounts. NASAB took part in these schemes. During his participation in the scheme, he was employed by Mahak Rayan Afraz, an Iran-based company that purported to provide cybersecurity services, but which was, in fact, a front for the conspirators’ operations. NASAB was responsible for procuring infrastructure used by the conspiracy. During the course of this conduct, NASAB used the stolen identity of a real person in order to register a server and email accounts used in the course of the cyber campaigns. * * * NASAB, 39, of Iran, is charged with one count of conspiracy to commit computer fraud, which carries a maximum sentence of five years in prison; one count of conspiracy to commit wire fraud, which carries a maximum sentence of 20 years in prison; one count of wire fraud, which carries a maximum sentence of 20 years in prison; and one count of aggravated identity theft, which carries a mandatory consecutive term of two years in prison. The maximum potential sentences in this case are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by the assigned judge. Concurrent with the unsealing of the Indictment, the Department of State’s Rewards for Justice Program is offering a reward of up to $10 million for information leading to the identification or location of NASAB. Anyone with information on NASAB and his malicious cyberactivity should contact Rewards for Justice via their Tor-based tips-reporting channel at: he5dybnt7sr6cm32xt77pazmtm65flqy6irivtflruqfc5ep7eiodiad.onion (the Tor browser is required). Mr. Williams praised the outstanding investigative work of the FBI, including the work of the FBI Cyber Division. The case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Ryan B. Finkel, Dina McLeod, and Daniel G. Nessim are in charge of the prosecution, with assistance from Trial Attorney Matthew Chang of the National Security Division’s Cyber Section. The charges contained in the Indictment are merely accusations, and the defendant is presumed innocent unless and until proven guilty. [1] As the introductory phrase signifies, the entirety of the text of the Indictment and the description of the Indictment set forth herein constitute only allegations, and every fact described should be treated as an allegation. Contact Nicholas Biase, Lauren Scarff (212) 637-2600 Updated February 29, 2024 Attachment U.S. v. Nasab Indictment [PDF, ] Topics Cybercrime National Security Component USAO - New York, Southern Press Release Number: 24-079
OCR text (8,782c · html-text · 99% conf)
Press Release U.S. Attorney Announces Charges Against Iranian National For Multi-Year Cyber Campaign Targeting U.S. Defense Contractors And Private Sector Companies Thursday, February 29, 2024 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Defendant Participated in Cyberattacks While Employed by Iranian Company That Purported to Provide Cybersecurity Services Damian Williams, the United States Attorney for the Southern District of New York; Matthew G. Olsen, the Assistant Attorney General for National Security; Bryan Vorndran, the Assistant Director of the Cyber Division of the Federal Bureau of Investigation (“FBI”); and James Smith, the Assistant Director in Charge of the New York Field Office of the FBI, announced today the unsealing of an Indictment charging Iranian citizen and resident ALIREZA SHAFIE NASAB for his involvement in a cyber-enabled campaign to compromise U.S. government and private entities, including the U.S. Departments of the Treasury and State, defense contractors, and two New York-based companies. The case has been assigned to U.S. District Judge Mary Kay Vyskocil. NASAB remains at large. U.S. Attorney Damian Williams said: “As alleged, Alireza Shafie Nasab participated in a cyber campaign using spearphishing and other hacking techniques to infect more than 200,000 victim devices, many of which contained sensitive or classified defense information. Cyber intrusion schemes such as the one alleged threaten our national security, and I’m proud of our law enforcement partners and the career prosecutors of this Office for using innovative technologies and investigative measures to disrupt and track down these cybercriminals.” Assistant Attorney General for National Security Matthew G. Olsen said: “While purporting to work as a cybersecurity specialist for Iran-based clients, Mr. Nasab allegedly participated in a persistent campaign to compromise U.S. private sector and government computer systems. Today’s charges highlight Iran’s corrupt cyber ecosystem, in which criminals are given free rein to target computer systems abroad and threaten U.S. sensitive information and critical infrastructure. Our National Security Cyber Section remains focused on disputing these cross-border hacking schemes and holding those responsible to account.” FBI Cyber Division Assistant Director Bryan Vorndran said: “The FBI will leverage all of our capabilities in combatting the threat waged by Iranian hacker organizations against America’s public and private sector. We encourage everyone to practice proper cyber hygiene to mitigate the risk of becoming vulnerable to malicious actors like Nasab. The close collaboration with partners that led to today’s unsealed indictment does not end there, and we are looking forward to continued teamwork in this space.” FBI New York Assistant Director in Charge James Smith said: “Hostile cybercriminals are determined to use hacking campaigns to harm public safety and threaten our national security. Alireza Nasab, over an extended number of years, allegedly participated in an aggressive campaign of cyberattacks targeting U.S. government agencies, defense contractors, and New York-based companies working closely with the Department of Defense. This case is a reminder that we all need to maintain proper cybersecurity and awareness to avoid falling victim to malicious cyber actors. The FBI will continue to lead the fight against hostile nation state actors attempting to harm our country in cyberspace.” According to the allegations contained in the Indictment unsealed today in Manhattan federal court:[1] From at least in or about 2016 through at least in or about April 2021, ALIREZA SHAFIE NASAB and other conspirators were members of a hacking organization that participated in a coordinated multi-year campaign to conduct and attempt to conduct computer intrusions. These intrusions targeted more than a dozen U.S. companies and the U.S. Departments of the Treasury and State. The hacking group’s private sector victims were primarily cleared defense contractors, which are companies that support U.S. Department of Defense programs. In addition, the group targeted a New York-based accounting firm and a New York-based hospitality company. In conducting their hacking campaigns, the group used spearphishing — that is, tricking an email recipient into clicking on a malicious link — to infect victim computers with malware. In the course of their campaigns against one victim, the group compromised more than 200,000 employee accounts. At another victim, the conspirators targeted 2,000 employee accounts. In order to manage their spearphishing campaigns, the group created and used a particular computer application, which enabled the conspirators to organize and deploy their spearphishing attacks. In the course of these spearphishing attacks, the conspirators compromised an administrator email account belonging to a defense contractor (“Defense Contractor-1”). Access to this administrator account empowered the conspirators to create unauthorized Defense Contractor-1 accounts, which the conspirators then used to send spearphishing campaigns to employees of a different defense contractor and a consulting firm. In addition to spearphishing, the conspirators utilized social engineering, which involved impersonating others, generally women, in order to obtain the confidence of victims. These social engineering contacts were another means the conspiracy used to deploy malware onto victim computers and compromise those devices and accounts. NASAB took part in these schemes. During his participation in the scheme, he was employed by Mahak Rayan Afraz, an Iran-based company that purported to provide cybersecurity services, but which was, in fact, a front for the conspirators’ operations. NASAB was responsible for procuring infrastructure used by the conspiracy. During the course of this conduct, NASAB used the stolen identity of a real person in order to register a server and email accounts used in the course of the cyber campaigns. * * * NASAB, 39, of Iran, is charged with one count of conspiracy to commit computer fraud, which carries a maximum sentence of five years in prison; one count of conspiracy to commit wire fraud, which carries a maximum sentence of 20 years in prison; one count of wire fraud, which carries a maximum sentence of 20 years in prison; and one count of aggravated identity theft, which carries a mandatory consecutive term of two years in prison. The maximum potential sentences in this case are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by the assigned judge. Concurrent with the unsealing of the Indictment, the Department of State’s Rewards for Justice Program is offering a reward of up to $10 million for information leading to the identification or location of NASAB. Anyone with information on NASAB and his malicious cyberactivity should contact Rewards for Justice via their Tor-based tips-reporting channel at: he5dybnt7sr6cm32xt77pazmtm65flqy6irivtflruqfc5ep7eiodiad.onion (the Tor browser is required). Mr. Williams praised the outstanding investigative work of the FBI, including the work of the FBI Cyber Division. The case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Ryan B. Finkel, Dina McLeod, and Daniel G. Nessim are in charge of the prosecution, with assistance from Trial Attorney Matthew Chang of the National Security Division’s Cyber Section. The charges contained in the Indictment are merely accusations, and the defendant is presumed innocent unless and until proven guilty. [1] As the introductory phrase signifies, the entirety of the text of the Indictment and the description of the Indictment set forth herein constitute only allegations, and every fact described should be treated as an allegation. Contact Nicholas Biase, Lauren Scarff (212) 637-2600 Updated February 29, 2024 Attachment U.S. v. Nasab Indictment [PDF, ] Topics Cybercrime National Security Component USAO - New York, Southern Press Release Number: 24-079