BLOCKLISTEDUSDTEthereum · Aug 24, 2026, 20:49:11 UTC
iransanctionscyber
Intelligence
Behzad Mezri (a.k.a. "Skote Vahshat")
Since at least summer 2023, Mojtaba Ghal’eh-Kuhi and Behzad Mesri have led a group of Iranian malicious cyber actors that includes Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, and Arman Kahzadian. This group frequently conducts computer network exploitations on behalf, or for the benefit, of Iran’s MOIS.
Event timeline
- Proposal submittedAug 24, 2026, 20:16:59 UTCsigner tx
- +0sSigner confirmationAug 24, 2026, 20:16:59 UTCsigner tx
- +29m 36sSigner confirmationAug 24, 2026, 20:46:35 UTCsigner tx
- +2m 36sSigner confirmationAug 24, 2026, 20:49:11 UTCsigner tx
- +0sExecuted on-chainAug 24, 2026, 20:49:11 UTCsigner tx
- Proposal submittedAug 24, 2026, 20:16:59 UTCsigner tx
- Signer confirmationAug 24, 2026, 20:16:59 UTC (+0s since previous)signer tx
- Signer confirmationAug 24, 2026, 20:46:35 UTC (+29m 36s since previous)signer tx
- Signer confirmationAug 24, 2026, 20:49:11 UTC (+2m 36s since previous)signer tx
- Executed on-chainAug 24, 2026, 20:49:11 UTC (+0s since previous)signer tx
Total elapsed (Δt):32m 12s
USDT escaped before freeze(left the address between proposal and execution)
$0.00
USDT received during the same window
$0.00
Address history
| Status | Asset | Balance | Date / Time | Tx Hash |
|---|---|---|---|---|
| BLOCKLISTED | USDC | $0.00 | Aug 24, 2026, 18:39:47 UTC | 0xf9f4…#251 |
| BLOCKLISTED | USDT | $660.04 | Aug 24, 2026, 20:49:11 UTC(this event) | 0x3f38…#766 |