Silent Librarian
MITRE ATT&CK: G0122 View on attack.mitre.org
Aliases: TA407, COBALT DICKENS, Mabna Institute, TA4900, Yellow Nabu, Mabna Institute Group, Silent Librarian
- First seen
- 2013-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:56:51
Targeted industries: education-and-nonprofits government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:au country_code:ca
Context
Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Librarian are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).
Detection coverage
- 71 Sigma rules
Malware & tools used
- Digital Certificates (attack-pattern)
- Search Victim-Owned Websites (attack-pattern)
- Email Collection (attack-pattern)
- Spearphishing Link (attack-pattern)
- Employee Names (attack-pattern)
- Email Forwarding Rule (attack-pattern)
- Email Accounts (attack-pattern)
- Email Addresses (attack-pattern)
- Link Target (attack-pattern)
- Password Spraying (attack-pattern)
- Domains (attack-pattern)
- Tool (attack-pattern)
- Valid Accounts (attack-pattern)
Reports & references
- info.phishlabs.com — Silent Librarian More To The Story Of The Iranian Mabna Institute Indictment (report)
- info.phishlabs.com — Silent Librarian University Attacks Continue Unabated In Days Following Indictment (report)
- justice.gov — Nine Iranians Charged Conducting Massive Cyber Theft Campaign Behalf Islamic (report)
- justice.gov — Nine Iranians Charged Conducting Massive Cyber Theft Campaign Behalf Islamic Revolutionary (report)
- secureworks.com — Cobalt Dickens Goes Back To School Again (report)
- secureworks.com — Back To School Cobalt Dickens Targets Universities (report)
- proofpoint.com — Seems Phishy Back School Lures Target University Students And Staff (report)
- proofpoint.com — Threat Actor Profile Ta407 Silent Librarian (report)
- secureworks.com — Cobalt Dickens (report)
- community.riskiq.com — 44Eb0802 (report)
- proofpoint.com — Iranian State Sponsored And Aligned Attacks What You Need Know And Steps Protect (report)
- MITRE ATT&CK — G0122 (report)
- blog.malwarebytes.com — Silent Librarian Apt Phishing Attack (report)
- justice.gov — Download (report)
External references
- mitre-attack — G0122
- TA407
- COBALT DICKENS
- DOJ Iran Indictments March 2018
- Phish Labs Silent Librarian
- Malwarebytes Silent Librarian October 2020
- Proofpoint TA407 September 2019
- Secureworks COBALT DICKENS August 2018
- Secureworks COBALT DICKENS September 2019
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy