Showing posts with label defense contractors. Show all posts
Showing posts with label defense contractors. Show all posts

Friday, March 1, 2024

Iranian National Charged For Multi-Year Hacking Campaign Targeting U.S. Defense Contractors And Private Sector Companies

 The U.S. Justice Department released the below information:

The Justice Department unsealed an indictment charging an Iranian national with involvement in a cyber-enabled campaign to compromise U.S. governmental and private entities, including the U.S. Departments of the Treasury and State, defense contractors, and two New York-based companies.

According to court documents, from at least in or about 2016 through in or about April 2021, Alireza Shafie Nasab, 39, of Iran, and other co-conspirators were members of a hacking organization that participated in a coordinated multi-year campaign to conduct and attempt to conduct computer intrusions. These intrusions targeted more than a dozen U.S. companies and the U.S. Departments of the Treasury and State. Nasab remains at large.

“While purporting to work as a cybersecurity specialist for Iran-based clients, Mr. Nasab allegedly participated in a persistent campaign to compromise U.S. private sector and government computer systems,” said Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division. 

“Today’s charges highlight Iran’s corrupt cyber ecosystem, in which criminals are given free rein to target computer systems abroad and threaten U.S. sensitive information and critical infrastructure. Our National Security Cyber Section remains focused on disputing these cross-border hacking schemes and holding those responsible to account.”

“As alleged, Alireza Shafie Nasab participated in a cyber campaign using spear phishing and other hacking techniques to infect more than 200,000 victim devices, many of which contained sensitive or classified defense information,” said U.S. Attorney Damian Williams for the Southern District of New York. “Cyber intrusion schemes such as the one alleged threaten our national security, and I’m proud of our law enforcement partners and the career prosecutors of this office for using innovative technologies and investigative measures to disrupt and track down these cybercriminals.”

“The FBI will leverage all of its capabilities in combating the threat posed by Iranian hacker organizations to America’s public and private sectors,” said Assistant Director Bryan Vorndran of the FBI’s Cyber Division. “The close collaboration with partners that led to today’s unsealed indictment of Alireza Shafie Nasab will continue to keep the pressure on cyber adversaries.”

The hacking group’s private sector victims were primarily cleared defense contractors, which are companies that support U.S. Department of Defense programs. In addition, the group targeted a New York-based accounting firm and a New York-based hospitality company.

According to the indictment, in conducting their hacking campaigns, the group used spear phishing — that is, tricking an email recipient into clicking on a malicious link — to infect victim computers with malware. In the course of their campaigns against one victim, the group compromised more than 200,000 victim employee accounts. At another victim, the conspirators targeted 2,000 employee accounts. In order to manage their spearphishing campaigns, the group created and used a particular computer application, which enabled the conspirators to organize and deploy their spear phishing attacks.

In the course of these spear phishing attacks, the conspirators compromised an administrator email account belonging to a defense contractor (Defense Contractor-1). Access to this administrator account empowered the conspirators to create unauthorized Defense Contractor-1 accounts, which the conspirators then used to send spear phishing campaigns to employees of a different defense contractor and a consulting firm.

In addition to spearphishing, the conspirators utilized social engineering, which involved impersonating others, generally women, in order to obtain the confidence of victims. These social engineering contacts were another means the conspiracy used to deploy malware onto victim computers and compromise those devices and accounts.

Nasab took part in these schemes. During his participation in the scheme, he was employed by Mahak Rayan Afraz, an Iran-based company that purported to provide cybersecurity services, but which was, in fact, a front for the conspirators’ operations. Nasab was responsible for procuring infrastructure used by the conspiracy. During the course of this conduct, Nasab used the stolen identity of a real person in order to register a server and email accounts used in the course of the cyber campaigns.

Nasab is charged with one count of conspiracy to commit computer fraud, which carries a maximum penalty of five years in prison; one count of conspiracy to commit wire fraud, which carries a maximum penalty of 20 years in prison; one count of wire fraud, which carries a maximum penalty of 20 years in prison and one count of aggravated identity theft, which carries a mandatory consecutive term of two years in prison. A federal district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors.

Concurrent with the unsealing of the indictment, the U.S. Department of State’s Rewards for Justice Program is offering a reward of up to $10 million for information leading to the identification or location of Nasab.

Anyone with information on Nasab and his malicious cyberactivity should contact Rewards for Justice via their Tor-based tips-reporting channel at:

he5dybnt7sr6cm32xt77pazmtm65flqy6irivtflruqfc5ep7eiodiad.onion (the Tor browser is required).

The FBI New York Field Office and Cyber Division are investigating the case.

Assistant U.S. Attorneys Ryan B. Finkel, Dina McLeod and Daniel G. Nessim for the Southern District of New York’s Complex Frauds and Cybercrime Unit are prosecuting the case, with valuable assistance from Trial Attorney Matthew Chang of the National Security Division’s National Security Cyber Section.

An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

Wednesday, February 25, 2015

Former Connecticut Resident Pleads Guilty To Attempting To Send Sensitive Military Documents To Iran


The U.S. Justice Department released the below information:

Assistant Attorney General for National Security John P. Carlin and U.S. Attorney Deirdre M. Daly for the District of Connecticut announced that Mozaffar Khazaee, 60, formerly of Manchester, Connecticut, pleaded guilty today before U.S. District Judge Vanessa L. Bryant in Hartford to violating the Arms Export Control Act, in connection with his efforts to send to Iran sensitive, proprietary, trade secret and export controlled material relating to military jet engines for the U.S. Air Force’s F35 Joint Strike Fighter program and the F-22 Raptor program, which he had stolen from defense contractors where he had previously been employed.

“While employed with U.S. defense contractors, Mozaffar Khazaee stole sensitive, proprietary and controlled technology to send it to Iran,” said U.S. Attorney Daly.  “The illegal export of our military technology compromises U.S. national security and reduces the advantages our armed forces currently possess.  As today’s case demonstrates, we will aggressively investigate and hold accountable those who attempt to steal trade secrets and sensitive military technology from U.S. industries, whether for their own personal gain or for the benefit of foreign actors.”

“Today’s guilty plea demonstrates the ongoing cooperation with our federal law enforcement partners to prevent U.S. technology from falling into the wrong hands,” said Special Agent in Charge Bruce Foucart of HSI Boston.  “Across the globe, the magnitude and scope of threats facing the United States has never been greater, and that's why one of Homeland Security Investigations highest priorities is to prevent illicit procurement networks, terrorist groups and hostile nations from illegally obtaining U.S. military products and sensitive dual-use technologies.  Homeland Security Investigations takes pride in protecting our country, and today’s guilty plea is the latest example of our effective investigative efforts.”

“This joint investigation has emphasized the need for American companies to remain vigilant against the theft of valuable and sensitive technologies,” said Special Agent in Charge Patricia M. Ferrick of the FBI’s New Haven Division.  “As our nation continues to lead the way in research and development, we are constantly reminded that there are those who seek to advance their own causes by stealing the hard work of others, and we owe it to ourselves and to the American public to guard against it. The FBI vigorously investigates these matters in cooperation with our law enforcement partners, both domestic and abroad.”

“This investigation demonstrates the dedication of the Department of Defense, Office of the Inspector General, Defense Criminal Investigative Service and our federal and military partners to ensure that critical technology is not exploited by criminals acting on behalf of governments hostile to the U.S.,” said Special Agent in Charge Craig W. Rupert of the Defense Criminal Investigative Service’s Northeast Field Office.  “Foreign governments continue to actively seek U.S. military technology in an effort to advance their own military development.  Today’s plea represents our continuing efforts to safeguard sensitive technology and to shield America’s investment in national defense by thwarting those who try to illegally acquire our national security assets.”

According to court documents and statements made in court, at different times between 2001 and 2013, Khazaee was employed by three separate defense contractors.  From at least 2009 through and including late 2013, Khazaee attempted to use trade secret, proprietary and export controlled material that he had obtained from his employers to gain employment in Iran.

In November and December 2009, Khazaee corresponded by email with an individual in Iran to whom he attempted to send, and in some cases did send, documents containing trade secret, proprietary and export controlled material relating to the Joint Strike Fighter Program.  In one email Khazaee wrote “some of these are very controlled . . . and I am taking [a] big risk.  Again please after downloading these two Power Point files delete everything immediately.”

Analysis of Khazaee’s computer media revealed not only additional documents containing proprietary, trade secret and export controlled material belonging to the U.S. defense contractors at which he had been employed, but also cover letters and application documents, dating from in or about 2009 through in or about 2013, in which Khazaee sought employment with multiple state-controlled technical universities in Iran.  In multiple letters Khazaee described the knowledge and skills he had obtained while working for the U.S. defense contractors and wrote:  “[a]s lead engineer in these projects I have learned some of the key technique[s] that could be transferred to our own industry and universities.”  Khazaee stated that he was “looking for an opportunity to work in Iran, and . . . transferring my skill and knowledge to my nation.”

In or about November 2013, while residing in Connecticut, Khazaee caused a shipment to be sent by truck from Connecticut to a freight forwarder located in Long Beach, California, which was intended for shipment to Iran.  The shipment included numerous boxes and digital media containing thousands of documents consisting of sensitive technical manuals, specification sheets, technical drawings and data, and other proprietary material relating to military jet engines and the United States Air Force’s F35 Joint Strike Fighter (JSF) program and the F-22 Raptor.  Many documents were labeled as “Export-Controlled,” as well as stamped with “ITAR-controlled” warnings.  Khazaee did not apply for nor did he obtain any export license or written authorization to export any of the documents, and the export or attempted export of such material to Iran is illegal.

On Jan. 9, 2014, Khazaee was arrested at the Newark Liberty International Airport before boarding a flight with a final destination of Iran.  Search warrants executed on Khazaee’s checked and carry-on luggage revealed additional sensitive, proprietary, trade secret and export controlled documents relating to military jet engines, in both hard copy and in electronic form on Khazaee’s computer media.  Khazaee has been detained since that time.

Judge Bryan scheduled sentencing proceedings for May 20, 2015, at which time Khazaee faces up to 20 years in prison and a $1,000,000 fine.

This investigation is being led by the United States Department of Homeland Security’s Homeland Security Investigations in New Haven, in coordination with the New Haven Division of the Federal Bureau of Investigation, the Defense Criminal Investigative Service in New Haven and the Department of Commerce’s Boston Office of Export Enforcement.

Assistant Attorney General Carlin joins U.S. Attorney Daly in commending the efforts of the many other agencies and offices that were involved in this investigation, including U.S. Attorney’s Offices for the Central District of California, the Southern District of Indiana and the District of New Jersey, Homeland Security Investigations in Los Angeles, the U.S. Customs and Border Protection Service in Los Angeles, the U.S. Air Force’s Office of Special Investigations in Los Angeles and Boston,  as well as HSI, CBP, and FBI in New Jersey, and HSI, FBI and DCIS in Indianapolis.

This case is being prosecuted by Assistant U.S. Attorneys Stephen Reynolds and Krishna Patel of the National Security and Major Crimes Unit of the District of Connecticut, and Trial Attorney Brian Fleming of the Justice Department’s National Security Division.

Tuesday, June 18, 2013

Operation Illwind: A Look Back At A Major Military Procurement Fraud Case


The FBI web site offered a piece on June 14th that looked back at Operation Illwind, the huge military procurement fraud case from 25 years ago.

Twenty-five years ago today, a major multi-agency investigation into defense procurement fraud—later codenamed Operation Illwind, a likely reference to an old English proverb—was announced to the world via a one-page press statement.

By the time the dust had settled several years later, the case revealed that some Defense Department employees had taken bribes from businesses in exchange for inside information on procurement bids that helped some of the nation’s largest military contractors win lucrative weapons systems deals.

More than 60 contractors, consultants, and government officials were ultimately prosecuted—including a high-ranking Pentagon assistant secretary and a deputy assistant secretary of the Navy. As a monetary measure of the significance of the crimes, the case resulted in a total of $622 million worth of fines, recoveries, restitutions, and forfeitures.

You can read the rest of the piece via the below link:

http://www.fbi.gov/news/stories/2013/june/a-byte-out-of-history-the-lasting-legacy-of-operation-illwind

Note: I recall Operation Illwind vividly, as I worked for a Defense Department command in Philadelphia that oversaw defense contractors at the time.

The above Defense Department photo shows an aerial view of the Pentagon.