Back to Intelligence

Iranian University Phishing Campaign Extradition: Detecting and Remediating Mailbox Credential Harvesting and Mass Email Exfiltration

SA
Security Arsenal Team
October 5, 2026
12 min read

Montenegro's courts have approved the extradition of Amir Barati — a 40-year-old dual Turkish-Iranian national — to the United States, where he faces charges tied to an Iranian state-aligned campaign that allegedly siphoned 31 terabytes of data from university email inboxes. Barati was arrested on June 25 and is now headed to face U.S. prosecution.

Let that number sink in: 31TB of email. That is not a smash-and-grab. That is a sustained, methodical collection operation against academic institutions — the kind of long-dwell intrusion that thrives in environments with sprawling identity estates, weak MFA coverage, legacy authentication protocols, and thousands of mailboxes owned by users who click links for a living. Universities are targeted precisely because they hold pre-publication research, intellectual property, grant data, and personal information on students and faculty — all behind defenses that are chronically underfunded relative to their intelligence value.

This extradition is not the end of a threat. The TTPs behind this campaign — spear-phishing with spoofed institutional login portals, credential harvesting, and bulk mailbox collection — remain in active use by Iranian-nexus actors (tracked variously as Silent Librarian / TA407 / Cobalt Dickens in academic targeting) and are trivially reusable against enterprises outside academia. If your organization runs Microsoft 365, Exchange, or Google Workspace, the detection and hardening guidance below applies to you today.

Technical Analysis

Who Was Targeted and Why

Academic institutions are a perennial priority for Iranian state-aligned intrusion sets. The objectives are consistent across campaigns:

  • Research theft — pre-publication papers, defense-adjacent research, engineering and scientific IP
  • Intelligence collection — communications of faculty working on topics of interest to Tehran (nuclear, regional security, sanctions evasion)
  • Credential recycling — harvested academic credentials are reused against government and private-sector targets via password reuse

The Attack Chain (Defender's View)

Based on the documented tradecraft of this actor cluster and the allegations in this case, the kill chain typically unfolds as follows:

  1. Reconnaissance (T1591/T1589): Operators scrape university websites and directories to build target lists of professors, researchers, and departmental staff, complete with names, titles, and institutional roles — everything needed for convincing pretexts.
  2. Spear-Phishing Delivery (T1566.002): Targets receive emails impersonating the university library system, IT helpdesk, or single sign-on (SSO) portal. Lures commonly reference expired library accounts, required re-validation, or shared documents. The phishing kit clones the institution's actual login page, often hosted on look-alike domains or compromised infrastructure.
  3. Credential Capture (T1056.003 / T1111): Victims authenticate to the cloned portal. Credentials — and in weaker deployments, session material — are captured in real time. Where MFA exists, actors use push-bombing, SIM-adjacent social engineering, or simply pivot to accounts without MFA coverage.
  4. Valid Account Access (T1078): Stolen credentials are replayed against Exchange Online / on-prem OWA, frequently via legacy protocols (IMAP, POP3, EWS) that bypass conditional access and don't support modern MFA.
  5. Collection (T1114 / T1114.002): Once inside, actors establish persistence and collection mechanisms: hidden inbox forwarding rules, delegated access, mass mailbox sync via IMAP, or mailbox export operations. At 31TB of stolen data, we are talking about sustained bulk synchronization of thousands of mailboxes over months or years — not opportunistic reads.
  6. Exfiltration (T1041 / T1567): Mail data is pulled to actor-controlled infrastructure, typically over the same protocols used for access (IMAP sync to attacker clients) or via web sessions to VPN/VPS egress points.

Exploitation Status

This is confirmed, real-world, and prosecuted activity — not theoretical. A named defendant is being extradited; the U.S. Department of Justice has a long track record of indictments against Iranian actors for this exact academic-targeting pattern (the 2018 nine-defendant case alone alleged theft of over 31TB from 144 U.S. universities — a figure matching this reporting). The actor cluster behind these campaigns remains active in 2026, spinning up new phishing infrastructure against universities each academic cycle. There is no CVE here — the vulnerability is identity posture, and it is fully within your control to fix.

Why Legacy Auth Is the Quiet Killer

The single most common enabler in these campaigns is legacy authentication: IMAP4, POP3, SMTP AUTH, and older Exchange Web Services clients that cannot enforce MFA or conditional access. An attacker with a stolen password and an open IMAP port owns the mailbox, full stop, and the sync traffic looks like a legitimate mail client. Closing legacy auth is the highest-leverage single control against this threat.

Detection & Response

The detections below target the three most reliable observable behaviors of this tradecraft: (1) malicious inbox rule creation for collection, (2) credential replay via legacy protocols and anomalous logon geographies, and (3) bulk mailbox export/sync activity.

YAML
---
title: Suspicious Inbox Forwarding or Redirect Rule Creation via PowerShell
id: 4d9e2b71-8c3a-4f6d-b2e5-7a1c9d3f0e12
status: experimental
description: Detects creation of inbox rules with forwarding/redirect actions, a common persistence and collection mechanism after mailbox compromise (MITRE T1098.002 / T1114.003). Frequently used by Iranian-nexus actors to silently copy victim mail to external addresses.
references:
  - https://attack.mitre.org/techniques/T1098/002/
  - https://attack.mitre.org/techniques/T1114/003/
author: Security Arsenal
date: 2026/02/10
tags:
  - attack.persistence
  - attack.collection
  - attack.t1098.002
  - attack.t1114.003
logsource:
  category: process_creation
  product: windows
detection:
  selection_cmdlet:
    CommandLine|contains:
      - 'New-InboxRule'
      - 'Set-InboxRule'
  selection_action:
    CommandLine|contains:
      - '-ForwardTo'
      - '-ForwardAsAttachmentTo'
      - '-RedirectTo'
  condition: selection_cmdlet and selection_action
falsepositives:
  - Helpdesk or Exchange administrators configuring transport or mailbox rules during legitimate onboarding
  - Automated provisioning scripts (baseline and exclude known admin hosts/accounts)
level: high
---
title: Legacy Protocol Authentication to Exchange (IMAP/POP) From Non-Standard Client
id: 8f3a6c24-1d5e-4b7a-9c81-2e6f0a4b8d35
status: experimental
description: Detects IMAP/POP authentication to Exchange Online, the primary channel for bulk mailbox sync after credential theft. Legacy protocols bypass MFA and conditional access and are the quiet enabler of mass email collection.
references:
  - https://attack.mitre.org/techniques/T1078/
  - https://attack.mitre.org/techniques/T1114/
author: Security Arsenal
date: 2026/02/10
tags:
  - attack.initial_access
  - attack.collection
  - attack.t1078
  - attack.t1114
logsource:
  product: azure
  service: signinlogs
detection:
  selection:
    ClientAppUsed:
      - 'IMAP4'
      - 'POP3'
      - 'SMTP'
      - 'Exchange Web Services'
      - 'Exchange ActiveSync'
      - 'Other clients'
  condition: selection
falsepositives:
  - Legitimate legacy mail clients and multifunction printers using SMTP AUTH (migrate and exclude; long-term goal is zero matches)
level: medium
---
title: Mailbox Export Request Initiated (Potential Bulk Email Collection)
id: b71f9e05-3c8d-4a26-9f54-1b8d2e6a0c49
status: experimental
description: Detects New-MailboxExportRequest execution, which can be abused to bulk-export mailbox contents to a PST file on a network share for exfiltration at scale.
references:
  - https://attack.mitre.org/techniques/T1114/002/
  - https://attack.mitre.org/techniques/T1530/
author: Security Arsenal
date: 2026/02/10
tags:
  - attack.collection
  - attack.exfiltration
  - attack.t1114.002
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains: 'New-MailboxExportRequest'
  condition: selection
falsepositives:
  - Legitimate eDiscovery, legal hold, or migration operations (tune to expected admin accounts and maintenance windows)
level: high
KQL — Microsoft Sentinel / Defender
// Hunt 1: Inbox rules forwarding or redirecting mail to external addresses (Office 365 audit)
// MITRE: T1098.002, T1114.003 — collection persistence after mailbox compromise
let lookback = 14d;
let internalDomains = dynamic(["yourdomain.edu", "yourdomain.com"]); // customize
OfficeActivity
| where TimeGenerated > ago(lookback)
| where Operation in ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules")
| extend RuleParams = tostring(Parameters)
| where RuleParams has_any ("ForwardTo", "ForwardAsAttachmentTo", "RedirectTo")
| extend ForwardTarget = tostring(parse_json(RuleParams))
| where not(RuleParams has_any (internalDomains))
| project TimeGenerated, UserId, ClientIP, Operation, RuleParams
| order by TimeGenerated desc;

// Hunt 2: Legacy protocol (IMAP/POP/SMTP-AUTH) sign-ins succeeding — credential replay indicator
// MITRE: T1078 — these bypass MFA; any success here is a finding worth triaging
SigninLogs
| where TimeGenerated > ago(7d)
| where ClientAppUsed in ("IMAP4", "POP3", "SMTP", "Exchange Web Services", "Other clients")
| where ResultType == 0
| summarize SignInCount = count(),
            DistinctIPs = dcount(IPAddress),
            IPs = make_set(IPAddress, 10),
            Countries = make_set(LocationDetails.countryOrRegion, 10)
    by UserPrincipalName, ClientAppUsed
| where SignInCount > 50 or DistinctIPs > 3   // bulk sync patterns / geo-diverse replay
| order by SignInCount desc;

// Hunt 3: Mailbox access from IPs with no prior history for that user (possible credential replay)
// MITRE: T1078, T1114
let historical =
    OfficeActivity
    | where TimeGenerated between (ago(90d) .. ago(8d))
    | where OfficeWorkload == "Exchange"
    | summarize KnownIPs = make_set(ClientIP) by UserId;
OfficeActivity
| where TimeGenerated > ago(7d)
| where OfficeWorkload == "Exchange"
| where Operation in ("MailItemsAccessed", "Bind", "Sync") // Bind/Sync = thick-client or IMAP sync
| join kind=leftouter historical on UserId
| where isnull(KnownIPs) or not(set_has_element(KnownIPs, ClientIP))
| summarize AccessCount = count(), Operations = make_set(Operation) by UserId, ClientIP
| where AccessCount > 100   // volume consistent with bulk collection, not casual reads
| order by AccessCount desc;
VQL — Velociraptor
-- Hunt for credential-phishing HTML artifacts (cloned login pages) saved to endpoints
-- and suspicious HTML files recently written to user-writable locations.
-- Phishing kits against universities are frequently opened from email attachments
-- or cached locally; this surfaces the endpoint-side residue of the lure.
SELECT
    FullPath,
    Size,
    Mtime AS ModifiedTime,
    Btime AS CreatedTime
FROM glob(
    globs=[
        'C:/Users/*/Downloads/*.html',
        'C:/Users/*/Desktop/*.html',
        'C:/Users/*/AppData/Local/Temp/*.html'
    ]
)
WHERE ModifiedTime > now() - (14 * 24 * 3600)
  AND FullPath !~ '(?i)google|microsoft|office|adobe'
ORDER BY ModifiedTime DESC

-- Companion hunt: recently executed processes from user-writable temp locations
-- (post-credential-theft tooling, archive staging for exfil)
SELECT
    Pid,
    Name,
    CommandLine,
    Exe,
    Username,
    CreateTime
FROM pslist()
WHERE Exe =~ '(?i)\\AppData\\(Local\\Temp|Roaming)\\'
   OR CommandLine =~ '(?i)(rar|7z|zip).*a .*\\Users\\.*\\(Documents|Desktop|AppData)'
ORDER BY CreateTime DESC
PowerShell
# ============================================================
# Mailbox Compromise Audit & Hardening — Exchange Online / M365
# Run from an elevated Exchange Online PowerShell session
# (Connect-ExchangeOnline first). Read-only audit + targeted fixes.
# ============================================================

# --- 1. AUDIT: Find all inbox rules forwarding/redirecting externally ---
Write-Host "[*] Auditing inbox forwarding rules across all mailboxes..." -ForegroundColor Cyan
$suspiciousRules = Get-Mailbox -ResultSize Unlimited | ForEach-Object {
    $mbx = $_.PrimarySmtpAddress
    Get-InboxRule -Mailbox $mbx -ErrorAction SilentlyContinue | Where-Object {
        $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo
    } | Select-Object @{n='Mailbox';e={$mbx}}, Name, ForwardTo, ForwardAsAttachmentTo, RedirectTo
}
$suspiciousRules | Export-Csv -Path ".\ExternalForwardingRules_$(Get-Date -Format 'yyyyMMdd').csv" -NoTypeInformation
$suspiciousRules | Format-Table -AutoSize

# --- 2. AUDIT: Confirm Unified Audit Log + MailItemsAccessed is enabled ---
Write-Host "[*] Checking audit configuration..." -ForegroundColor Cyan
$auditConfig = Get-AdminAuditLogConfig
Write-Host "UnifiedAuditLogIngestionEnabled: $($auditConfig.UnifiedAuditLogIngestionEnabled)"
if (-not $auditConfig.UnifiedAuditLogIngestionEnabled) {
    Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
    Write-Host "[+] Unified Audit Log ingestion ENABLED." -ForegroundColor Green
}

# --- 3. HARDEN: Disable legacy authentication org-wide ---
# Create/apply an authentication policy blocking IMAP, POP, SMTP AUTH, EWS legacy
Write-Host "[*] Blocking legacy authentication protocols..." -ForegroundColor Cyan
$policyName = "Block-Legacy-Auth"
if (-not (Get-AuthenticationPolicy -Identity $policyName -ErrorAction SilentlyContinue)) {
    New-AuthenticationPolicy -Name $policyName `
        -AllowBasicAuthImap $false `
        -AllowBasicAuthPop $false `
        -AllowBasicAuthSmtp $false `
        -AllowBasicAuthWebServices $false `
        -AllowBasicAuthPowershell $false `
        -AllowBasicAuthActiveSync $false
}
Get-Mailbox -ResultSize Unlimited | Set-Mailbox -AuthenticationPolicy $policyName
Write-Host "[+] Legacy auth blocked for all mailboxes." -ForegroundColor Green

# --- 4. HARDEN: Disable automatic external forwarding at the transport level ---
Write-Host "[*] Disabling automatic forwarding to external domains..." -ForegroundColor Cyan
Set-HostedOutboundSpamFilterPolicy -Identity Default -AutoForwardingMode Off
Write-Host "[+] External auto-forwarding disabled (AutoForwardingMode = Off)." -ForegroundColor Green

# --- 5. VERIFY: List mailboxes with forwarding SMTP addresses set ---
Write-Host "[*] Checking mailbox-level forwarding (ForwardingSmtpAddress)..." -ForegroundColor Cyan
Get-Mailbox -ResultSize Unlimited |
    Where-Object { $_.ForwardingSmtpAddress -or $_.ForwardingAddress } |
    Select-Object PrimarySmtpAddress, ForwardingSmtpAddress, ForwardingAddress, DeliverToMailboxAndForward |
    Format-Table -AutoSize

# --- 6. AUDIT: Recent MailItemsAccessed / suspicious operations (last 7 days) ---
Write-Host "[*] Searching audit log for mailbox export and mass-access events..." -ForegroundColor Cyan
Search-UnifiedAuditLog -StartDate (Get-Date).AddDays(-7) -EndDate (Get-Date) `
    -Operations "New-MailboxExportRequest","MailItemsAccessed","UpdateInboxRules" `
    -ResultSize 5000 |
    Export-Csv -Path ".\MailboxAudit_$(Get-Date -Format 'yyyyMMdd').csv" -NoTypeInformation
Write-Host "[+] Audit exports written to working directory. Review for anomalies." -ForegroundColor Green

Remediation

This campaign exploited no software flaw — it exploited identity configuration debt. Remediate in this order:

  1. Kill legacy authentication immediately. Block IMAP4, POP3, SMTP AUTH, and legacy EWS org-wide via authentication policies (script above) and Microsoft Entra Conditional Access. This single control collapses the primary access vector for bulk mailbox collection. Microsoft has been deprecating Basic Auth for Exchange Online — verify your tenant has no lingering exceptions.
  2. Enforce phishing-resistant MFA. Move from SMS/voice/push MFA to FIDO2 security keys or certificate-based authentication, prioritizing faculty, researchers, and administrators. Credential-harvesting kits defeat passwords; they do not defeat hardware-bound passkeys. Number-matching push is the bare minimum interim step.
  3. Disable automatic external forwarding. Set AutoForwardingMode to Off at the outbound spam filter policy, alert on any inbox rule with forward/redirect actions, and routinely audit ForwardingSmtpAddress attributes. Collection via forwarding rules only works if you let it.
  4. Alert on bulk access patterns. Enable and monitor MailItemsAccessed audit events (requires appropriate licensing), and baseline normal sync volumes per user. A mailbox suddenly syncing 50,000 items via IMAP from a new geography is a page-worthy event, not a log entry.
  5. Phishing-resistant perimeter for the lure itself. Deploy DMARC enforcement (p=reject) on institutional domains, configure external-sender bannering, and train users specifically on SSO/library-portal lures — the exact pretext used here. Run simulated campaigns mimicking cloned institutional login pages, not generic prize scams.
  6. Assume credential compromise and hunt accordingly. If your institution appeared in any academic-targeting threat reporting, force password resets with session revocation (Revoke-AzureADUserAllRefreshToken) for exposed populations, and retro-hunt sign-in logs for legacy-protocol access over the past 90 days.
  7. Report and coordinate. Academic institutions should engage with the Research and Education Networks ISAC (REN-ISAC) and FBI field offices on suspected Iranian-nexus intrusions — these investigations, like the Barati case, are built from victim reporting.

There are no vendor patches or CVEs to apply — the "patch" is identity hygiene, and the deadline was yesterday.

Related Resources

Security Arsenal Alert Triage Automation AlertMonitor Platform Book a SOC Assessment platform Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.