Silent Librarian

MITRE ATT&CK: G0122 View on attack.mitre.org

Aliases: TA407, COBALT DICKENS, Mabna Institute, TA4900, Yellow Nabu, Mabna Institute Group, Silent Librarian

First seen
2013-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:56:51

Targeted industries: education-and-nonprofits government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:au country_code:ca

Context

Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Librarian are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).

Detection coverage

  • 71 Sigma rules

Malware & tools used

  • Digital Certificates (attack-pattern)
  • Search Victim-Owned Websites (attack-pattern)
  • Email Collection (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Employee Names (attack-pattern)
  • Email Forwarding Rule (attack-pattern)
  • Email Accounts (attack-pattern)
  • Email Addresses (attack-pattern)
  • Link Target (attack-pattern)
  • Password Spraying (attack-pattern)
  • Domains (attack-pattern)
  • Tool (attack-pattern)
  • Valid Accounts (attack-pattern)

Reports & references

  • info.phishlabs.com — Silent Librarian More To The Story Of The Iranian Mabna Institute Indictment (report)
  • info.phishlabs.com — Silent Librarian University Attacks Continue Unabated In Days Following Indictment (report)
  • justice.gov — Nine Iranians Charged Conducting Massive Cyber Theft Campaign Behalf Islamic (report)
  • justice.gov — Nine Iranians Charged Conducting Massive Cyber Theft Campaign Behalf Islamic Revolutionary (report)
  • secureworks.com — Cobalt Dickens Goes Back To School Again (report)
  • secureworks.com — Back To School Cobalt Dickens Targets Universities (report)
  • proofpoint.com — Seems Phishy Back School Lures Target University Students And Staff (report)
  • proofpoint.com — Threat Actor Profile Ta407 Silent Librarian (report)
  • secureworks.com — Cobalt Dickens (report)
  • community.riskiq.com — 44Eb0802 (report)
  • proofpoint.com — Iranian State Sponsored And Aligned Attacks What You Need Know And Steps Protect (report)
  • MITRE ATT&CK — G0122 (report)
  • blog.malwarebytes.com — Silent Librarian Apt Phishing Attack (report)
  • justice.gov — Download (report)

External references