2024-02-29 DOJ SDNY indictment 132 KB 15,150 chars

United States v. ALIREZA SHAFIE NASAB, Southern District of New York (Feb. 29, 2024) — Indictment

raw: United States v Alireza Shafie Nasab, Superseding Indictment S2 21 Cr 704

United States v Alireza Shafie Nasab, Superseding Indictment S2 21 Cr 704 (S.D.N.Y. Feb. 29, 2024)

Caption
UNITED STATES OF AMERICA v. ALIREZA SHAFIE NASAB
summary

Alireza Shafie Nasab, an Iranian national, was charged with conspiracy to commit computer intrusions and wire fraud for participating in a multi-year hacking campaign against U.S. agencies and companies.

paragraph

Alireza Shafie Nasab faces charges of conspiracy to commit computer intrusions, wire fraud, and aggravated identity theft for his role in a hacking campaign active from 2016 to 2021. The indictment alleges he procured infrastructure for spearphishing and social engineering attacks that targeted U.S. federal agencies and private defense contractors. The scheme involved compromising over 200,000 employee accounts at a New York accounting firm and caused damages exceeding $5,000.

narrative

Alireza Shafie Nasab, an Iranian national, has been charged in a superseding indictment with conspiracy to commit computer intrusions, wire fraud, and aggravated identity theft. Between 2016 and 2021, Nasab participated in a coordinated hacking campaign targeting U.S. federal agencies, including the Departments of State and Treasury, as well as cleared defense contractors. The conspiracy utilized spearphishing and social engineering, including the use of female personas on social media, to compromise thousands of accounts. Notably, the campaign breached a New York-based accounting firm, compromising over 200,000 employee accounts, and a hospitality company. Nasab, who worked for the Iran-based cybersecurity firm Mahak Rayan Afraz, is accused of procuring infrastructure for these attacks and using a real person's identity to register servers. The government seeks the forfeiture of all property and proceeds derived from these criminal activities.

Enriched metadata

Scheme
cyber-fraud (97%)
Court
Southern District of New York
Outcome
indicted
Classified cyber-fraud(confidence 97%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Statutes
Title 18, United States Code, Sections 1030(a)Title 18, United States Code, Section 371Title 18, United States Code, Section 1343Title 18, United States Code, Section 1349Title 18, United States Code, Section 3238Title 18, United States Code, Section 1028ATitle 18, United States Code, Sections 1028A(a)Title 18, United States Code, Section 981(a)Title 28, United States Code, Section 2461(c)Title 21, United States Code, Section 853(p)Title 28, United States Code, Section 246l(c)Title 18, United States Code, Sections 981Title 21, United States Code, Section 853Title 28, United States Code, Section 2461
Parties
United States of AmericaALIREZA SHAFIE NASAB
Keywords
title codeleast aboutalireza shafieshafie nasabemail accountsaccountsaboutconspiracynasabmembers conspiracyemailusednewalirezatitle

Extracted insights

Dollar amounts 1
  • $5K $5,000 <$10K
Entities 4
  • person alireza shafie nasab
  • person cleared defense contractors
  • person conspiracy members
  • person hacking organization
Triples 10
  • Alireza Shafie Nasab is national of Islamic Republic Of Iran
  • Alireza Shafie Nasab member of Hacking Organization
  • Hacking Organization conducted computer intrusions into More Than A Dozen American Companies And U.S. Departments Of Treasury And State
  • Hacking Organization campaign duration 2016 Through April 2021
  • Conspiracy Members targeted Cleared Defense Contractors
  • Conspiracy Members compromised accounts at New York Accounting Firm (200,000+ Employee Accounts)
  • Conspiracy Members targeted accounts at Hospitality Company-1 (2,000+ Employee Accounts)
  • Conspiracy Members created and used Application-1 For Spearphishing Campaign Management
  • Conspiracy Members compromised administrator account at Defense Contractor-1 In August 2019
  • Conspiracy Members targeted Defense Contractor-1, Defense Contractor-2, And Consulting Firm-1 (February 2019 - December 2019)
Text layers
Extracted body text (15,150c)

UNITED STATES DISTRICT COURT 
SOUTHERN DISTRICT 
OF NEW YORK 
-------------------------------------X 
UNITED STATES OF AMERICA 
-v.-
ALIREZA SHAFIE NASAB, 
Defendant. 
-------------------------------------X 
COUNT ONE 
SEALED 
SUPERSEDING 
INDICTMENT 
S2 21 Cr. 704· 
(Conspiracy to Commit Computer Intrusions) 
The Grand Jury charges: 
OVERVIEW 
1. From at least in or about 2016 through at least in or about April 2021, ALIREZA 
SHAFIE NASAB 
(~ ~ t...a_»lc ), the defendant, a national of the Islamic Republic of Iran, and 
others known and unknown, were members 
of a  hacking organization that participated in a 
coordinated, multi-year campaign to conduct and attempt computer intrusions into more than a 
dozen American companies and the U.S. Departments 
of the Treasury and State. 
2. The private sector victims were primai·ily cleai·ed defense contractors, which were 
granted security clearances by the U.S. Department 
of Defense to access, receive, and store 
classified information for the purpose 
of conducting activities in suppo1t of U.S. Defense 
Department programs. Other private sector victims included a  New York, 
New York-based 
accounting firm, where more than 200,000 employee accounts were compromised, and a  New 
York, 
New York-based hospitality company ("Hospitality Company-I"), where more than 2,000 
employee accounts were targeted for compromise. 

MEANS AND METHODS OF THE CONSPIRACY 
Spearphishing 
3. In conducting their hacking campaign, one of the means through which members 
of the conspiracy obtained and sought to obtain unauthorized access to victim systems was through 
the use 
of spearphishing. • In a spearphishing campaign, a malicious actor sends an email or other 
online message to a victim, which message attempts to trick the victim into either clicking a link 
that will download malicious software  ("malware") onto the victim's computer or unwittingly 
providing account credentials 
(i.e., usemame and password) to the malicious actor. 
4. Members 
of the conspiracy created, and used, a particular computer application 
("Application-1 ") to manage their many spearphishing campaigns. Application-1 enabled 
members 
of the conspiracy to obtain a  report of various target email accounts for different 
campaigns (including whether a particular target email account clicked the malicious hyperlink 
in 
spearphishing emails as well as the victim Internet protocol ("IP") address, victim location, the 
web browser used by the victim, and the victim's operating system). Application-I also allowed 
conspiracy members to select which email accounts to target  and then launch spearphishing 
attacks. 
5. In many instances, members of the conspiracy registered domains that were 
designed to mimic the domains 
of victim entities or other known corporate entities, to trick 
recipients into believing that the spearphishing emails came from a  trusted source. In other 
instances, members 
of the conspiracy leveraged compromised accounts, or fraudulently created 
accounts 
on victim systems, to use those accounts, and the associated authentic and trusted 
domains, to targe{ additional victims. 
2 

6. For example, between in or about February 2019 and in or about December 2019, 
members 
of the conspiracy targeted two cleared defense contractors ("Defense Contractor-I" and 
"Defense Contractor-2") and a consulting firm ("Consulting Firm-I").  In or about August 2019, 
the conspirators compromised an administrator email account belonging to Defense Contractor-
I. 
After obtaining unauthorized access to that account, the conspirators used the account's 
administrator privileges to create two new unauthorized Defense Contractor-I email accounts.  The 
conspirators then used those two fraudulent email accounts to send spearphishing emails to 
employees 
of Defense Contractor-2 and Consulting Firm-1, in the course of attempting to 
compromise the computer systems 
of Defense Contractor-2 and Consulting Firm-I. 
Social Engineering 
7. Members of the conspiracy also used social engineering, which is the use of 
deception to manipulate individuals into divulging confidential or personal information, in order 
to gain unauthorized access to victim accounts and networks. Generally, the conspirators sent 
messages to victims from conspirator-created social media accounts with female personas. These 
messages often contained links to a  malicious domain or attached documents embedded with 
malware. 
8. For example,  the conspirators used social engineering involving a female persona 
to induce an employee 
at Defense Contractor-2 to click on a link in a web form. Shortly thereafter, 
members 
of the conspiracy compromised that employee's account at Defense Contractor-2. 
THE DEFENDANT 
9. At all-times relevant to this Superseding Indictment ("Indictment"), ALIREZA 
SHAFIE NASAB, the defendant, participated in the above-described highly organized and 
coordinated scheme to conduct computer intrusions targeting American companies and federal 
3 

agencies, as well as Country-1. During his involvement in the crimes charged in this Indictment, 
NASAB worked for Iran-based private technology companies, and was responsible for procuring 
infrastructure used by the conspiracy, particularly infrastructure used 
in furtherance of social 
engineering campaigns. NASAB also used the identity 
of a real person ("Individual-I"), including 
Indivdiual-1 
's name and passport, to register server and email accounts that were used in the course 
of cyber campaigns. 
10. 
At certain times relevant to this Superseding Indictment, Mahak Rayan Afraz{~ 
jl.)I 0YI.J) ("MRA") was an Iran-based company that purpo1ied to provide cybersecurity services. 
ALIREZA SHAFIE NASAB worked 
at MRA, including at times during which he engaged in the 
conspiracy described 
in this Superseding Indictment. 
STATUTORY ALLEGATIONS 
11. From at least in or about 2016 through at least in or about April 2021, in the 
Southern District 
of New York and elsewhere, ALIREZA SHAFIE NASAB, the defendant, and 
others known and unknown, willfully and knowingly combined, conspired, confederated, and 
agreed together and with each other to commit offenses against the United States, to wit, a 
computer intrusion and intentionally causing damage to a  computer system, 
in violation of Title 
18, United States Code, Sections 1030(a)(4), 1030(c)(3)(A), 1030(a)(5)(A), 1030(c)(4)(A)(i)(I), 
and 1030(c)(4)(B)(i) and (ii). 
12. 
It was a part and an object of the conspiracy that ALIREZA SHAFIE NASAB, the 
defendant, and others known and unknown, knowingly and with the intent to defraud, would and 
did access a  protected computer without authorization, and exceed authorized access, and 
by 
means of such conduct further the intended fraud and obtain anything of value, in violation of Title 
18, United States Code, Sections 1030(a)(4) and (c)(3)(A). 
4 

13. It was further a  part and an object of the conspiracy that ALIREZA SHAFIE 
NASAB, the defendant, and others lmown and unlmown, lmowingly would and did cause the 
transmission 
of a  program, information, code, and command, and as a  result of such conduct, 
would and did intentionally cause damage, without authorization, to a protected computer, which 
caused a loss (including loss resulting from a  related course 
of conduct affecting one and more 
other protected computers) aggregating to at least $5,000 in value to one and more persons during 
any one-year period, 
in violation of Title 18, United States Code, Sections 1030(a)(5)(A), 
1030( c )( 4)(A)(i)(I), and 1030( c )( 4)(B)(i). 
Overt Acts 
14. In furtherance 
of the conspiracy and to effect the illegal objects thereof, the 
following overt acts, among  others, were committed in the Southern District 
of New York and 
elsewhere:. 
a. In or about December 2018, members of the conspiracy sent spearphishing 
emails and two documents embedded with malware to an email account 
of Hospitality Company-
1 located in New York, New York. 
· 
b. In or about September 2019, members of.the conspiracy compromised an 
administrator account at Defense Contractor-1, used that account to create two new unauthorized 
email accounts 
on Defense Contractor-I 's system, and then used those fraudulent email accounts 
to send spearphishing emails to additional victims. 
c. In or about September 2020, ALIREZA SHAFIE NASAB, the defendant, 
registered an account with an internet-service provider that leased IP addresses used 
as part of 
social engineering attacks against employees at a domestic cleared defense contractor. 
(Title 18, United States Code, Section 371.) 
5 

COUNT TWO 
(Conspiracy to Commit  Wire Fraud) 
The Grand Jury further charges: 
15. The allegations contained in paragraphs 1  through 10 of this Indictment are 
repeated and realleged 
as if fully set forth herein. 
16. From 
at least in or about 2016 through at least in or about April 2021, in the 
Southern District of New York and elsewhere, ALIREZA SHAFIE NASAB, the defendant, and 
others known and unknown, willfully and knowingly combined, conspired, confederated, and 
agreed together and with each other to commit wire fraud, in violation 
of Title 18, United States 
Code, Section 1343. 
17. It  was a  part and object 
of the conspiracy that ALIREZA SHAFIE NASAB, the 
defendant, and others known and unknown, knowingly having devised and intending to devise a 
scheme and artifice to defraud and for obtaining money and property by means 
of false and 
fraudulent pretenses, representations, and promises, would and did transmit and cause to be 
transmitted 
by means of wire, radio, and television communication in interstate and foreign 
commerce, writings, signs, signals, pictures, and sounds for the purpose 
of executing such scheme 
and artifice, 
in violation of Title 18, United States Code, Section 1343, to wit, NASAB and others 
engaged in a  scheme to use fraudulent means, including spearphishing, to obtain dominion and 
control over victim email accounts, and to create fraudulent email accounts 
on victim computer 
systems, with the intention 
of using those fraudulent email accounts to compromise other online 
accounts belonging to the same victim and other victims, which involved the use 
of interstate wires 
into and out 
of the Southern District of New York. 
(Title 18, United States Code, Section 1349.) 
6 

The Grand Jury further charges: 
COUNT THREE 
(Wire Fraud) 
18. The allegations contained in paragraphs I  through 10 of this Indictment are 
repeated and realleged as 
if fully set forth herein. 
19. From at least 
in or about May 2014 through at least in or about April 2017, in the 
Southern District 
of New York and elsewhere, ALIREZA SHAFIE NASAB, the defendant, who 
will first 
be brought to the Southern District of New York, knowingly having devised and intending 
to devise a scheme and artifice to defraud, and for obtaining money and property by means 
of false 
and fraudulent pretenses, representations, and promises, transmitted and caused to 
be transmitted 
by means 
of wire, radio, and television communication in interstate and foreign commerce, 
writings, signs, signals, pictures, and sounds for the purpose 
of executing such scheme and artifice, 
to wit, NASAB and others engaged 
in a scheme to use fraudulent means, including spearphishing, 
to obtain dominion and control over victim email accounts, and to create fraudulent email accounts 
on victim computer systems, with the intention 
of using those fraudulent email accounts to 
compromise other online accounts belonging to the same victim and other victims, which involved 
the use 
of interstate wires into and out of the Southern District of New York. 
(Title 18, United States Code, Sections 1343 and 
2; 
Title 18, United States Code, Section 3238.) 
COUNT FOUR 
(Aggravated Identity Theft) 
The Grand Jury further charges: 
20. •  The allegations contained 
in paragraphs I  through· 10 of this Indictment are 
repeated and realleged as 
if fully set forth herein. 
7 

21. From at least in or about 2017 through at least in or about 2019, in the Southern 
District 
of New York and elsewhere, ALIREZA SHAFIE NASAB, the defendant, knowingly 
transferred, possessed, and used, without lawful authority, a means 
of identification of another 
person, during and in relation to a felony violation enumerated in Title 18, United States Code, 
Section 1028A( c ), and aided and abetted the same, to wit, NASAB transferred, possessed, and 
used, and aided and abetted the transfer, possession, and use of, the name and passport 
of 
Individual-I to register server and email accounts that were used for operational purposes during 
and 
in relation to the computer fraud and wire fraud offenses charged in Counts Two and Three of 
this Indictment. 
(Title 18, United States Code, Sections 1028A(a)(l), 
1028A(b), and 2.) 
FORFEITURE ALLEGATIONS 
22. As a result 
of committing the computer fraud offenses alleged in Count One of this 
Indictment, ALIREZA SHAFIE NASAB, the defendant, shall forfeit to the United States, pursuant 
to Title 18, United States· Section, Section 
103 0(i), any and all property, real or personal, 
constituting or d~rived from, any proceeds obtained directly or indirectly, as a  result 
of said 
offense, and any and all personal property that was used or intended to 
be used to commit or to 
facilitate the commission of said offense, including but not limited to a sum of money in United 
·States cutTency representing the amount 
of proceeds traceable to the commission of said offense. 
23. As a result 
of committing the wire fraud offenses alleged in Counts Two and Three 
of this Indictment, ALIREZA SHAFIE NASAB, the defendant, shall forfeit to the United States, 
pursuant to Title 
18, United States Code, Section 981(a)(l)(C), and Title 28, United States Code, 
Section 2461(c), any and all property, real and personal, which  constitutes or is derived from 
8 

proceeds traceable to the commission said offenses, including but not limited to a sum of money 
in United States currency representing the amount 
of proceeds traceable to the commission of said 
offenses. 
Substitute Assets Provision 
24. 
If any of the above-described forfeitable property, as a result of any act or omission 
of the defendant: 
a. cannot be located upon the exercise of due diligence; 
b. has been transferred or sold to, or deposited with, a third person; 
c. has been placed beyond the juris_diction of the Court;. 
d. has been substantially diminished in value; 
or 
e. has been commingled with other property which cannot be 
subdivided without difficulty; 
I 
it is the intent of the United States, pursuant to Title 21, United States Code, Section 853(p), and 
Title 28, United States Code, Section 246l(c), to seek forfeiture 
of any other property of the 
defendant up to the value 
of the above forfeitable property. 
(Title 
18, United States Code, Sections 981 & 1030; . 
Title 21, United States Code, Section 853; and 
Title 28, United States Code, Section 2461
.) 
9 
... 
~~~ 
DAMIAN WILLIAMS 
United States Attorney