The United States Department of Justice unsealed an 18-count federal indictment on Friday charging three computer hackers working on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) with orchestrating a wide-ranging cyber espionage and hack-and-leak conspiracy targeting former President Donald Trump's 2024 presidential campaign.

Announcing the charges in Washington alongside FBI Director Christopher Wray, Attorney General Merrick Garland identified the defendants as Masoud Jalili, 36, Seyyed Ali Aghamiri, 34, and Yaser Balaghi, 37. Federal prosecutors allege the trio operated within a specialized cyber unit known in the cybersecurity community as Mint Sandstorm or APT42, directed by the IRGC Intelligence Organization.

Inside the IRGC Spear-Phishing and Credential-Theft Operation

According to court filings unsealed in the District of Columbia, the operatives began targeting former US national security officials, military personnel, and political campaign advisers as early as January 2020. Using tailored social-engineering lures, spoofed login portals, and compromised email accounts of trusted associates, the group successfully breached the personal email accounts of senior officials connected to the Trump campaign in May and June.

Once inside the compromised accounts, the operatives exfiltrated internal campaign strategy documents, candidate vetting dossiers, and confidential scheduling communications. Prosecutors detailed how the conspirators subsequently used fictitious online personas to peddle the stolen materials to American journalists and individuals associated with President Joe Biden's campaign—none of whom replied to or utilized the unsolicited messages.

“The Justice Department will not tolerate attempts by an authoritarian regime to exploit our democratic process through state-sponsored cyber espionage and hack-and-leak operations.”

Concurrent Treasury Sanctions and Ten-Million-Dollar Rewards

The indictment charges Jalili, Aghamiri, and Balaghi with conspiracy to commit wire fraud, aggravated identity theft, unauthorized access to protected computers, and providing material support to a designated foreign terrorist organization. Because all three defendants are believed to reside in Iran, federal authorities placed them on the FBI's Most Wanted cyber fugitives list.

In coordinated actions, the US Department of the Treasury's Office of Foreign Assets Control (OFAC) imposed financial sanctions on the three indicted hackers and four additional IRGC-linked officials, while the State Department's Rewards for Justice program announced a reward of up to $10 million for actionable intelligence leading to their location or arrest.

Sources