THREAT_ACTOR · G0122
Silent Librarian
Also known as: Silent Librarian, TA407, COBALT DICKENS
Profile
Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Librarian are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).
MITRE ATT&CK ↗Techniques
13 ATT&CK techniques attributed to this actor.
T1078 Valid AccountsT1110.003 Password SprayingT1114 Email CollectionT1114.003 Email Forwarding RuleT1583.001 DomainsT1585.002 Email AccountsT1588.002 ToolT1588.004 Digital CertificatesT1589.002 Email AddressesT1589.003 Employee NamesT1594 Search Victim-Owned WebsitesT1598.003 Spearphishing LinkT1608.005 Link Target
Related corpus activity
2,052 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Silent Librarian.
Showing the top 30 by severity of 2,052.