The U.S. Department of the Treasury announced that it has placed two Iranians on its sanctions list in connection with ransomware activities. In a statement released on Wednesday, December 7, on its official website, the two individuals, 'Ali Kharashadi Zadeh and Mohammad Ghorbaniyan', are identified as acting on behalf of 'notorious cyber actors from Iran'. These individuals have been involved in the 'SamSam ransomware' program, which has victimized over 200 individuals. The U.S. Treasury states that the mentioned individuals assisted in converting ransom payments made in the cryptocurrency 'Bitcoin' into Iranian Rial. All assets and interests derived from the assets of sanctioned individuals that are in the possession or control of U.S. persons or within the territory of the United States are frozen, and U.S. persons are prohibited from engaging in any transactions with them. The statement adds that the Office of Foreign Assets Control has identified two cryptocurrency addresses associated with these financial facilitators. They have conducted over seven thousand transactions in Bitcoin through these addresses, valued at millions of U.S. dollars. The U.S. Treasury claims that some of these ransomware attacks were carried out using SamSam ransomware and Bitcoin. According to released information, this ransomware encrypts the victim's system data and demands hefty sums for the decryption keys. This amount is typically over five thousand dollars, which is significantly higher than the usual ransom demands. The U.S. Treasury statement indicates that Kharashadi Zadeh and Ghorbaniyan have been central to the successes of the SamSam ransomware, assisting cyber officers in converting Bitcoin ransoms into Iranian Rial and depositing them in Iranian banks. In this context, the U.S. Department of Justice also pursued two hackers on Wednesday for multiple intrusions into the information networks of the United States, the United Kingdom, and Canada since 2015 using SamSam ransomware. The Associated Press reported the names of the two suspects as 'Faramerz Shahsavandi', 34, and 'Mohammad Mahdi Shah Mansouri', 27, stating that they have earned six million dollars through this method. It is suspected that these two individuals, who are fugitives, may be in Iran. Sigal Mandelker, Deputy Assistant Secretary for Terrorism and Financial Intelligence at the Treasury, stated in a release: 'The Treasury targets cryptocurrency exchangers who have assisted Iranian cyber actors in converting digital ransom payments from their victims. As Iran becomes increasingly isolated and deprived of access to U.S. dollars, it is crucial to make virtual currency exchanges, network exchangers, and other cryptocurrency service providers more resilient against these illegal schemes.' He added that his department has revealed the cryptocurrency addresses of illegal actors in the cryptocurrency space, stating: 'The Treasury is actively pursuing Iran and other rogue regimes that seek to exploit cryptocurrencies and undermine them to achieve their nefarious objectives.' The department emphasized that 'SamSam ransomware has victimized companies, hospitals, universities, and government agencies, holding the data of over 200 victims hostage for financial exploitation.' According to the U.S. Treasury, cyber officers exploited vulnerabilities in computer networks to activate this ransomware, installing it within the network without the consent of the computer owners. They then demanded that victims pay ransoms in Bitcoin to regain access to their computer information and control their networks again. According to the statement, Kharashadi Zadeh and Ghorbaniyan have been central to the successes of the SamSam ransomware, assisting cyber officers in converting Bitcoin ransoms into Iranian Rial and depositing them in Iranian banks. The sanctions on Wednesday mark the fourth round of U.S. sanctions against the Islamic Republic of Iran within the past month. Since the Trump administration took office in 2016, the Office of Foreign Assets Control of the Treasury has sanctioned over 900 individuals, entities, aircraft, and vessels for activities related to Iran's support for terrorism, ballistic missile programs, proliferation of weapons, cyber attacks, criminal financial activities, censorship, and human rights violations.
The U.S. Sanctions Two Iranians in Connection with 'SamSam Ransomware' and Converting Bitcoin to Rial
The U.S. Treasury has sanctioned two Iranians linked to the SamSam ransomware, which has affected over 200 victims. They are accused of converting ransom payments from Bitcoin to Iranian Rial. This move is part of ongoing U.S. efforts to combat cybercrime and restrict Iran's financial operations.
👥 Key Players
⚡ Actions
📰 What Happened
U.S. sanctions two Iranians linked to SamSam ransomware and Bitcoin conversion activities.
- U.S. Department of the Treasury sanction Ali Kharashadi Zadeh, Mohammad Ghorbaniyan
- U.S. Department of the Treasury announce Ali Kharashadi Zadeh, Mohammad Ghorbaniyan
- U.S. Department of Justice indict Faramerz Shahsavandi, Mohammad Mahdi Shah Mansouri
💡 Why It Matters
📚 Background
The U.S. is actively pursuing individuals linked to ransomware and cryptocurrency conversion in Iran.
📝 Key Evidence
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%