Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States. He’s a dual Turkish and Iranian citizen, 40 years old, picked up by Montenegro’s Police Directorate after the FBI issued a warrant.
“He is accused of committing the following crimes: conspiracy to commit computer fraud and computer hacking, as well as identity theft, by conducting massive hacking attacks on the infrastructure of the United States of America since 2013, as an associate of a legal entity from the territory of Iran – at over 150 universities in the United States of America, causing damage estimated at more than 3.4 billion US dollars.” reads the press release published by Montenegro’s Police.
Barati’s hacking career reportedly began in Iran, where he founded the Iran Black Hats Team and later co-founded Digital Boys Underground Team. Archived records linked the groups to attacks on academic, commercial and government targets, including NASA, Microsoft and MIT. After his 2010 arrest by Iran’s Intelligence Ministry, sources said he was recruited as an intelligence asset, although this could not be independently confirmed. Iran International reports that Barati left Iran for Turkey in 2021, gained Turkish citizenship and changed his name. He was later arrested while on holiday in Montenegro. A US indictment subsequently linked him to the Mabna network and its alleged IRGC-backed campaign targeting universities.
Barati was arrested in Kotor, a coastal town in Montenegro, while he was on vacation.
In August, the US Justice Department named him in a 14-count indictment against 17 people. Prosecutors allege they were part of an operation run through the Iranian Mabna Institute on behalf of the Islamic Revolutionary Guard Corps.
The scale of the campaign was significant. Prosecutors say the group hacked email accounts at universities and research institutions around the world and stole at least 31 terabytes of data. US officials estimate the damage at $3.4 billion.
The targets weren’t random, either. Academic journals, theses, dissertations, electronic books, pulled from 144 American universities and 42 US companies, plus 178 foreign universities and at least 11 foreign companies. Between 2013 and 2017, the campaign allegedly compromised roughly 8,000 professor email accounts, using stolen credentials to get in and stay in.
Prosecutors describe Barati as directly involved in the operation, not just someone working in the background. The Record Media quoted the government saying he helped track the progress of the spearphishing campaigns. He also allegedly shared stolen credentials with other members, built lists of targets, carried out network reconnaissance, and wrote phishing emails himself.
According to the DOJ, the stolen data was sent to the Iranian government and also sold through two websites to universities in Iran. One of those sites allowed users to log in to US university library systems using stolen credentials belonging to professors. The affected universities also spent about $20 million investigating the attacks and repairing the damage.
Iran International’s reporting shows that Barati’s hacking activities go back years before the current indictment. He reportedly became known in Iran’s hacking scene and founded groups including the Iran Black Hats Team and the Digital Boys Underground Team. Both groups have been accused of targeting organizations such as Microsoft and MIT.
Iran International also confirmed that Montenegro plans to extradite Barati to the United States.
“Montenegro will extradite Iranian-Turkish hacker Amir Barati to the United States, where he faces charges over a sweeping cyber campaign that US prosecutors say stole research and data for Iran’s Revolutionary Guards and other entities.” state Iran International.
Barati now faces multiple counts of conspiracy to commit computer intrusions, wire fraud, computer fraud, and identity theft. Full reporting and the extradition order:
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Iranian hacker)