Skip to content

Operation Economic Outcast: MOIS-directed critical-infrastructure cyber group designated in "Economic D-Day" sanctions

Summary

On August 24, 2026, the U.S. Treasury announced Operation Economic Outcast, a whole-of-government economic campaign against Iran and its enablers that press secretary Scott Bessent framed as an "Economic D-Day." As part of the action, OFAC designated nearly 60 entities, individuals, and vessels across nuclear and missile procurement, cyber, and oil/shadow-fleet networks, and issued five sectoral sanctions determinations under E.O. 13902 (digital assets, technology, gold, aviation, shipping) that expand secondary-sanctions exposure for anyone operating in those Iranian sectors.

The cyber component is the durable threat-intelligence item: OFAC designated a malicious cyber group directed by Iran's Ministry of Intelligence and Security (MOIS) that is "responsible for extensive compromises of U.S. critical infrastructure and financially motivated cyber theft." The action was taken in coordination with the FBI, which on August 18, 2026 unsealed a superseding indictment charging 17 Iranian cyber actors, four of whom were designated on the same day. The five named individuals are alleged members of the Tehran-based Mabna Institute: Behzad Mesri, Mojtaba Ghal'eh-Kuhi, Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, and Arman Kahzadian. The State Department concurrently designated seven Iran defense-leadership members and two entities, and its Rewards for Justice program now offers up to $10 million for information on foreign-government-directed malicious cyber activity against U.S. critical infrastructure.

Tags

What was designated

The August 24 OFAC action (press release sb0613) targets three network families under four authorities — E.O. 13382 (WMD proliferators and means of delivery), E.O. 13694 as amended (malicious cyber-enabled activities), E.O. 13902 (Iranian economy sectoral), and E.O. 13224 (counterterrorism):

  • The MOIS itself, designated under E.O. 13694 as amended, E.O. 13224, and E.O. 13553 for cyber activity threatening U.S. national security, support to multiple terrorist groups, and complicity in serious human-rights abuses. This builds on the September 18, 2023 E.O. 14078 designation tied to the detention and probable murder of former FBI Special Agent Robert A. "Bob" Levinson.
  • The MOIS-directed cyber group (details below).
  • A nuclear/missile procurement network of 20+ entities and individuals spanning the UAE, Hong Kong, China, Singapore, and elsewhere — front companies (Sweet Ocean Industrial Limited, RPT Technology, Shenzhen Sweet Ocean, Tiany Technology, MT Trading, BRE Line and related) that procured proliferation-sensitive equipment (laser optics, accelerometers, actuators) for U.S./UN/EU-sanctioned Malek Ashtar University of Technology and other MODAFL-subordinate end users.
  • Iran's shadow-fleet oil-revenue network — vessel brokers and financial intermediates (including Fattouh/Amdeh, Obukhov/Foscom FZE, Azure Shipping and related) that move Iranian crude and channel revenue to the IRGC-QF and regime elements.

Separately, OFAC suspended several general licenses that had authorized certain remittance payments to Iran and Iranian access to the U.S. cultural/academic system, and issued additional guidance on sanctions risks for bowing to Iranian Strait-of-Hormuz shipping demands.

The MOIS-directed cyber group

Per the OFAC release, since at least summer 2023 Mojtaba Ghal'eh-Kuhi and Behzad Mesri have led a group that includes Ghareh Blagh, Shahbazi Balujeh, Kadkhoda'i, and Kahzadian. The group "frequently conducts computer network exploitations on behalf, or for the benefit, of Iran's MOIS." Key points from the designation:

  • Behzad Mesri was previously designated twice — March 23, 2018 under E.O. 13694 as amended (targeting and attempted extortion of a U.S. media and entertainment company, publicly reported as HBO) and February 13, 2019 under E.O. 13606 (acting for sanctioned Net Peygard Samavat Company).
  • Ghareh Blagh, Shahbazi Balujeh, and Kadkhoda'i conduct the majority of the group's network-compromise activity. Since at least late 2023 they successfully compromised and exfiltrated data from multiple U.S. companies in critical-infrastructure sectors — energy companies, defense contractors, healthcare institutions, IT companies, and financial institutions. In summer 2024 they compromised multiple local, state, and federal government offices across the U.S.
  • Ghal'eh-Kuhi and Shahbazi Balujeh compromised and exfiltrated data from an Iranian telecommunications company in spring 2025 — the release notes some members prioritize personal profit over MOIS tasking and have targeted Iranian companies.
  • Arman Kahzadian focused on digital-asset heists; in summer 2023 he illicitly gained control of a wallet holding over $30,000 in Bitcoin.
  • TRM Labs analyzed the 30 wallets linked to the five Mabna members: roughly $16.8 million total received; Ghareh Blagh's 10 addresses received 15.5 million (units as reported by TRM; 92% of the network's on-chain volume) between January 6, 2018 and August 20, 2026; Mesri's 15 addresses received $1.2 million between July 12, 2019 and August 22, 2026; combined residual balance $202,662.

Designation basis: Ghareh Blagh, Shahbazi Balujeh, Kadkhoda'i, and Ghal'eh-Kuhi under E.O. 13694 as amended (cyber-enabled activities threatening U.S. national security that harm services supporting critical-infrastructure sectors); Kahzadian under the same authority for misappropriation of funds/information through cyber-enabled means.

Indictment and reward context

  • The FBI announced on August 18, 2026 the unsealing of a superseding indictment against 17 Iranian cyber actors; four of the 17 are the designated individuals. The OFAC release does not publish the full 17-person list or counts, so this wiki does not assert further indictment detail.
  • The Rewards for Justice program announced a reward of up to $10 million for information on any person who, acting at the direction or under the control of a foreign government, engages in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act.

Relation to the broader Iran-linked picture

This designation is a named-industry, named-person anchor for the multi-cluster Iran landscape documented in July 2026. Public attribution since the February 2026 U.S./Israeli airstrikes on Iran includes breaches of 30+ water and wastewater utilities in 12+ U.S. states, the breach of the FBI director's personal email account, and a suspected-Iran 4-day shutdown of a small UK power plant. SentinelOne's July assessment framed the landscape as multiple clusters with distinct missions and tradecraft, with access optionality as the principal strategic risk. The OFAC release's "critical infrastructure + financial motivation" framing is consistent with the espionage-plus-greed profile already seen in the Handala, Cavern Manticore, and Seedworm / MuddyWater pages; the water-sector PLC campaign of July–August 2026 is tracked separately in that page. Attribution of the specific water-utility incidents to this named group is not established in the OFAC release; preserve that distinction.

Why this matters for defenders

  • Named-critical-infrastructure compromise is now official U.S. government fact, not vendor attribution. U.S. critical-infrastructure organizations (energy, defense, healthcare, IT, finance) and government offices should treat the August 2026 MOIS designation as a confirmed threat to their sector and re-baseline: assume the named group can hold long-term access from at least late 2023, and prioritize dwell-time hunting, credential/session auditing, and exfiltration-path review over first-day-of-incident response only.
  • Government-office intrusions (summer 2024) expand the threat to local/state/federal facilities, including their OT/ICS-adjacent environments; the concurrent water-sector PLC activity shows how such access overlaps with physical-infrastructure risk.
  • Financial motivation is part of the model. Expect extortion/leak monetization of stolen data alongside espionage, and treat the 30 linked wallets and $16.8M flow as a live detection surface (wallets, exchange on-ramps, and residual-balance movements are monitorable even without attribution).
  • Secondary-sanctions determinations raise the cost of facilitation. Digital-asset platforms, shipping, aviation, and gold/technology operators serving Iran face expanded enforcement risk; compliance teams should re-scope Iran-related facilitation after the five sectoral determinations.

Scope and evidence limits

  • This page records the OFAC/DOJ public action and THN's summary reporting. It does not assert the full 17-person indictment list, specific victim names, tooling, or infrastructure; none of that is in the public release at capture time.
  • The TRM Labs wallet analysis is third-party blockchain forensics, not a government finding; wallet linkage to individuals reflects TRM's attribution methodology.
  • Sectoral and individual determinations expand legal exposure; they are not claims that the named individuals' operations are confined to the described sectors or time windows.
  • The OFAC release does not name which of the 17 indicted are the four designated; this page follows THN's reporting that the five named individuals (Mabna Institute) were indicted.

Sources

  • U.S. Department of the Treasury / OFAC, "Treasury Launches Unprecedented Campaign Against Iranian Regime on Economic D-Day" (sb0613), August 24, 2026: https://home.treasury.gov/news/press-releases/sb0613
  • The Hacker News, "U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches," August 25, 2026: https://thehackernews.com/2026/08/us-sanctions-iran-linked-hackers-behind.html
  • U.S. Department of State, Rewards for Justice program announcement (up to $10M for foreign-government-directed malicious cyber activity against U.S. critical infrastructure), August 2026
  • U.S. Department of Justice / FBI, superseding indictment of 17 Iranian cyber actors, announced August 18, 2026