Silent Librarian
Aliases: TA407, COBALT DICKENS
Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Librarian are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).
Open interactive actor investigation
ATT&CK techniques
T1588.004
Digital CertificatesT1594
Search Victim-Owned WebsitesT1114
Email CollectionT1598.003
Spearphishing LinkT1589.003
Employee NamesT1114.003
Email Forwarding RuleT1585.002
Email AccountsT1589.002
Email AddressesT1608.005
Link TargetT1110.003
Password SprayingT1583.001
DomainsT1588.002
ToolT1078
Valid Accounts
Digital CertificatesT1594
Search Victim-Owned WebsitesT1114
Email CollectionT1598.003
Spearphishing LinkT1589.003
Employee NamesT1114.003
Email Forwarding RuleT1585.002
Email AccountsT1589.002
Email AddressesT1608.005
Link TargetT1110.003
Password SprayingT1583.001
DomainsT1588.002
ToolT1078
Valid Accounts