Silent Librarian is an Iran-linked threat actor known for stealing intellectual property primarily from universities.
Analyst brief
Silent Librarian (also tracked as COBALT DICKENS, TA407) is an Iran-linked threat actor primarily targeting universities, private companies, and government agencies. Their key TTPs include spearphishing links, password spraying, and email collection via forwarding rules to steal intellectual property. Defenders should focus on protecting academic credentials, enforcing multi-factor authentication, and monitoring for unauthorized email forwarding rules.
Silent Librarian
COBALT DICKENSMabna InstituteTA407
unknown
Last Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute. According to prosecutors, the defendants stole more than 31 terabytes of data from universities, companies, and government agencies around the world. The cost to the universities alone reportedly amounted to approximately $3.4 billion. The information stolen from these universities was used by the Islamic Revolutionary Guard Corps (IRGC) or sold for profit inside Iran. PhishLabs has been tracking this same threat group since late-2017, designating them Silent Librarian. Since discovery, we have been working with the FBI, ISAC partners, and other international law enforcement agencies to help understand and mitigate these attacks.
Monitor email collection and forwarding rules to detect suspicious email activity.
FAQ2
Which sectors does Silent Librarian primarily target?+
Silent Librarian primarily targets universities, private companies, and government agencies.
What key defense recommendations are provided for Silent Librarian?+
Defenders should focus on protecting academic credentials, enforcing multi-factor authentication (MFA), and monitoring for unauthorized email forwarding rules.