Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Silent Librarian

Also known as: TA407, COBALT DICKENS, Silent Librarian, Mabna Institute, TA4900, Yellow Nabu, Mabna Institute Group

Description

Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Librarian are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).(Citation: DOJ Iran Indictments March 2018)(Citation: Phish Labs Silent Librarian)(Citation: Malwarebytes Silent Librarian October 2020)

Goals & Targeting

Targeted Sectors

Government

Targeted Countries / Regions

US

AI Analysis

· 1 week ago

Executive Summary

Silent Librarian, also known as TA407, COBALT DICKENS, Mabna Institute Group, and Yellow Nabu, is a state-sponsored advanced persistent threat (APT) group linked to cyber espionage activities targeting research institutions, government agencies, and private companies. The group has been active since at least 2013 and is suspected to be associated with the Islamic Revolutionary Guard Corps (IRGC) based in Iran.

Goals & Targeting

Silent Librarian's strategic goals appear to be centered around collecting sensitive information and intellectual property from targeted sectors such as government and academia. Their targeting profile suggests a focus on countries with significant research and development capabilities, particularly the US. The group's activities align with broader Iranian interests in gaining economic and military advantages through cyber espionage.

Enhanced Description

Silent Librarian has consistently focused on infiltrating organizations to collect sensitive data, intellectual property, and research findings. Their activities have primarily targeted universities, government entities, and private sector companies across various countries, including the United States. The group is known for leveraging sophisticated tactics to achieve their objectives while maintaining a low profile. They are associated with the Mabna Institute, an Iranian entity that has been implicated in numerous cyber espionage campaigns on behalf of the IRGC.

Key Capabilities

  • Spearphishing
  • Password Spraying
  • Email Collection

ATT&CK Techniques

Reconnaissance
4 techniques
Resource Development
5 techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. DOJ Iran Indictments March 2018 — DOJ. (2018, March 23). U.S. v. Rafatnejad et al . Retrieved February 3, 2021.
  2. Phish Labs Silent Librarian — Hassold, Crane. (2018, March 26). Silent Librarian: More to the Story of the Iranian Mabna Institute Indictment. Retrieved February 3, 2021.
  3. Malwarebytes Silent Librarian October 2020 — Malwarebytes Threat Intelligence Team. (2020, October 14). Silent Librarian APT right on schedule for 20/21 academic year. Retrieved February 3, 2021.
  4. Proofpoint TA407 September 2019 — Proofpoint Threat Insight Team. (2019, September 5). Threat Actor Profile: TA407, the Silent Librarian. Retrieved February 3, 2021.
  5. Secureworks COBALT DICKENS August 2018 — Counter Threat Unit Research Team. (2018, August 24). Back to School: COBALT DICKENS Targets Universities. Retrieved February 3, 2021.
  6. Secureworks COBALT DICKENS September 2019 — Counter Threat Unit Research Team. (2019, September 11). COBALT DICKENS Goes Back to School…Again. Retrieved February 3, 2021.

Intel Summary

13

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

APT
Government Targeting

Details

MITRE ID
G0122
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--90784c1e-4aba-40eb-9adf-7556235e6384
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.