← Back to the index

Editorial

Iran Imports China's Playbook — The Barati Arrest and the Mabna Institute

An Iranian national arrested in Montenegro, a 2018 US indictment thread reaching back to Tehran, 31 terabytes of stolen research data over eight years. Kim Zetter traces how Iran — around 2013, the same year Mandiant exposed China as APT-1 — appears to have imported an economic-espionage playbook from Beijing. What that means for German universities and research institutions.

Published by NEOSEC Redaktion
iranaptwirtschaftsspionagehochschuleirgcmabna-institutekommentar

"One of the largest state-sponsored hacking campaigns ever prosecuted." — US Department of Justice on the 2018 indictment of nine Iranian nationals, as cited in Kim Zetter, "Arrest of Iranian Hacker Spotlights Iran's Movement into Economic Espionage and IP Theft", Zero Day, 1 July 2026

One detail from Kim Zetter's piece deserves the attention of every German research CIO: when the US Department of Justice indicted nine Iranian nationals in 2018 for attacks against more than 300 universities worldwide, 176 of those institutions were located outside the US — spread across roughly two dozen countries. Germany is on the list by name. Specific German institutions are not named in the public record, but given the geographic reach and the focus disciplines — engineering, medicine, natural and social sciences — it is a question of probability, not possibility, that German houses were among the victims.

The occasion for Zetter's report is the arrest of Amir Barati, a 39-year-old Iranian-Turkish national, in Montenegro last week at the request of the FBI. Barati is alleged to have attacked more than 150 US universities since 2013 on behalf of Iran''s Islamic Revolutionary Guard Corps (IRGC) and Iranian universities. The claimed damages: 3.4 billion US dollars — a figure that matches, to the digit, the 2018 case against the so-called Mabna Institute of Tehran, a company US prosecutors say was founded around 2013 for the express purpose of stealing academic intellectual property from foreign targets on behalf of Iranian state and private clients.

The Barati arrest is therefore likely the first visible instrument through which the Mabna case turns, eight years after indictment, from mostly sealed dockets into a courtroom appearance.

What Zetter argues — and why it matters for Germany

Zetter draws a notable parallel: the Mabna Institute was founded "in approximately 2013". 2013 is also the year Mandiant published the APT-1 report, the first comprehensive public exposure of China''s state-sponsored economic-espionage program. Her thesis, openly framed as a question: did Tehran look at China and reorient its own capabilities in the same direction?

Before that, Zetter notes, Iranian cyber activity abroad was primarily characterised by DDoS campaigns against US banks, the intrusion into a small SCADA-controlled dam in New York State, the ransomware wave against 200 US municipalities and hospitals, and the 2020 election-influence operations. The long reach into academic and industrial research data is a new emphasis — and one that should recalibrate the German threat picture.

Because while Germany''s domestic intelligence agency (Bundesamt für Verfassungsschutz) has for years warned in its annual economic-security reports about Chinese innovation extraction, and has actively engaged universities through its Wirtschaftsschutz outreach programme, the Iranian component of this conversation has remained largely at the margins. The Barati case makes it plain that Iranian activity is not only real but has been methodical for more than a decade — targeted at the very sector that carries the backbone of German innovation: Fraunhofer, Helmholtz, Max-Planck, DFG-funded research consortia, technical universities.

The attack vector is unspectacular, and that''s why it works

On the attack vector shown by the 2018 Mabna indictment, there is little surprising — and therefore no ground for comfort. The attackers sent spear-phishing emails that looked like collegial citation notes: "I read your recent paper on X, would you like to discuss?", followed by a link to a spoofed library or publisher login page. Whoever entered their university credentials there handed over not only their own account but access to library resources, publisher databases, grant-management platforms, and email mailboxes.

Of 100 000 accounts targeted, roughly 8 000 were compromised according to the indictment, about half of them belonging to US professors. On many of those accounts, the attackers set up automatic forwarding rules — a persistence technique still poorly detected by most SIEM rule sets deployed in university environments.

The attack requires no zero-days. It requires patience, good target research on ORCID profiles and conference programmes, decent English — and a large enough target set for the probability distribution to work.

Iran is not China — what that relativises, and what it doesn''t

Zetter herself flags an important difference at the end of her piece: Iranian operations appear less mature, technically and organisationally, than Chinese ones. China operates through a constellation of front companies, MSS-linked hackers, and PLA-adjacent contractors in a clear hierarchy. Iran has Mabna, has IRGC-adjacent contractor firms, has other semi-state cyber units — but the line between contract theft in state interest and contract theft in university private interest is considerably blurrier.

This lower maturity does not translate into lower effectiveness. Thirty-one terabytes of stolen research data from a single institute over eight years speaks plainly. The maturity question matters for defensive prioritisation — an institution defending itself against Chinese activity with a full kill-chain toolkit will stop Iran at a fraction of the effort. But "lower maturity" is not the same thing as "lower ambition", and the ambition is strategic: technological catch-up in a sanctions-heavy environment.

What German research institutions should do concretely

Four operational anchors emerge from the 2018 indictment that translate directly to the German context:

  1. Harden library and publisher login flows. Shibboleth SSO with hardware-based MFA is the only robust answer to credential phishing. Anyone still accessing JSTOR, Elsevier, or Springer with username plus password in 2026 is playing a game the 2013 attackers already win.
  2. Actively detect auto-forward rules. In Exchange and Google Workspace: every newly created forwarding rule must fire an alert, and external forwarding should be policy-blocked, not merely "recommended off".
  3. Spear-phishing awareness for postdocs, PhD students, research staff. Targets are not the vice-chancellors and deans, but the people with access rights to journals and datasets. Awareness training has to reach them.
  4. Use BSI and BfV Wirtschaftsschutz as partners. Both offer free consultation. A phone call is cheaper than a terabyte of stolen dissertation data.

What the Barati case additionally signals

Barati was arrested in Montenegro because Iran has no extradition treaty with the US — arrests are only feasible when the person leaves the country. That explains why, eight years after the 2018 indictment, only now is someone in a courtroom, and why the 2020 indictment of three Iranians in the satellite sector has yet to see a single defendant behind a Western cell door.

For the defender side, this is humbling more than reassuring. Iranian economic-espionage operations are in all likelihood running undisturbed while case files pile up. The only lever where German institutions can actually improve their position is their own hardening — not waiting on Western law enforcement.

Zetter''s piece is, in this respect, a useful reality check at the midpoint of 2026: anyone still holding "Iran = DDoS and ransomware" in their head is lagging the situation by more than a decade.


Source (English only): Kim Zetter, "Arrest of Iranian Hacker Spotlights Iran''s Movement into Economic Espionage and IP Theft", Zero Day, 1 July 2026. Details on the 2018 case drawn from the SDNY indictment (US v. Rafatnejad et al.).