SYMBOLCOMMON_NAMEaka. SYNONYMS

Silent Librarian  (Back to overview)

aka: COBALT DICKENS, Mabna Institute, TA407

Last Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute. According to prosecutors, the defendants stole more than 31 terabytes of data from universities, companies, and government agencies around the world. The cost to the universities alone reportedly amounted to approximately $3.4 billion. The information stolen from these universities was used by the Islamic Revolutionary Guard Corps (IRGC) or sold for profit inside Iran. PhishLabs has been tracking this same threat group since late-2017, designating them Silent Librarian. Since discovery, we have been working with the FBI, ISAC partners, and other international law enforcement agencies to help understand and mitigate these attacks.


Associated Families

There are currently no families associated with this actor.


References
2020-12-02RiskIQCorian Kennedy
@online{kennedy:20201202:shadow:76686c6, author = {Corian Kennedy}, title = {{Shadow Academy: Hiding in the shadows of Mabna Institute}}, date = {2020-12-02}, organization = {RiskIQ}, url = {https://community.riskiq.com/article/44eb0802}, language = {English}, urldate = {2020-12-10} } Shadow Academy: Hiding in the shadows of Mabna Institute
Silent Librarian
2020SecureworksSecureWorks
@online{secureworks:2020:cobalt:db17357, author = {SecureWorks}, title = {{COBALT DICKENS}}, date = {2020}, organization = {Secureworks}, url = {https://www.secureworks.com/research/threat-profiles/cobalt-dickens}, language = {English}, urldate = {2020-05-23} } COBALT DICKENS
Silent Librarian
2019-10-14ProofpointProofpoint Threat Insight Team
@online{team:20191014:threat:42bffb4, author = {Proofpoint Threat Insight Team}, title = {{Threat Actor Profile: TA407, the Silent Librarian}}, date = {2019-10-14}, organization = {Proofpoint}, url = {https://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-ta407-silent-librarian}, language = {English}, urldate = {2019-10-18} } Threat Actor Profile: TA407, the Silent Librarian
Silent Librarian
2019-09-11SecureworksCTU Research Team
@online{team:20190911:cobalt:7ecb95c, author = {CTU Research Team}, title = {{COBALT DICKENS Goes Back to School…Again}}, date = {2019-09-11}, organization = {Secureworks}, url = {https://www.secureworks.com/blog/cobalt-dickens-goes-back-to-school-again}, language = {English}, urldate = {2020-01-08} } COBALT DICKENS Goes Back to School…Again
Silent Librarian
2019-09-05ProofpointMichael Walsh, Proofpoint Threat Insight Team
@online{walsh:20190905:seems:5cb0fb8, author = {Michael Walsh and Proofpoint Threat Insight Team}, title = {{Seems Phishy: Back to School Lures Target University Students and Staff}}, date = {2019-09-05}, organization = {Proofpoint}, url = {https://www.proofpoint.com/us/threat-insight/post/seems-phishy-back-school-lures-target-university-students-and-staff}, language = {English}, urldate = {2019-11-26} } Seems Phishy: Back to School Lures Target University Students and Staff
Silent Librarian
2018-08-24SecureworksCTU Research Team
@online{team:20180824:back:baf0f3b, author = {CTU Research Team}, title = {{Back to School: COBALT DICKENS Targets Universities}}, date = {2018-08-24}, organization = {Secureworks}, url = {https://www.secureworks.com/blog/back-to-school-cobalt-dickens-targets-universities}, language = {English}, urldate = {2019-12-06} } Back to School: COBALT DICKENS Targets Universities
Silent Librarian
2018-04-05PhishLabsCrane Hassold
@online{hassold:20180405:silent:288fac9, author = {Crane Hassold}, title = {{Silent Librarian University Attacks Continue Unabated in Days Following Indictment}}, date = {2018-04-05}, organization = {PhishLabs}, url = {https://info.phishlabs.com/blog/silent-librarian-university-attacks-continue-unabated-in-days-following-indictment}, language = {English}, urldate = {2019-10-23} } Silent Librarian University Attacks Continue Unabated in Days Following Indictment
Silent Librarian
2018-03-26PhishLabsCrane Hassold
@online{hassold:20180326:silent:9ce69cd, author = {Crane Hassold}, title = {{Silent Librarian: More to the Story of the Iranian Mabna Institute Indictment}}, date = {2018-03-26}, organization = {PhishLabs}, url = {https://info.phishlabs.com/blog/silent-librarian-more-to-the-story-of-the-iranian-mabna-institute-indictment}, language = {English}, urldate = {2020-01-07} } Silent Librarian: More to the Story of the Iranian Mabna Institute Indictment
Silent Librarian
2018-03-23Department of JusticeDepartment of Justice
@online{justice:20180323:nine:51c3fd6, author = {Department of Justice}, title = {{Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps}}, date = {2018-03-23}, organization = {Department of Justice}, url = {https://www.justice.gov/opa/pr/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary}, language = {English}, urldate = {2019-12-17} } Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps
Silent Librarian
2018-03-23United States Department of JusticeUnited States Department of Justice
@online{justice:20180323:nine:51457d0, author = {United States Department of Justice}, title = {{Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps}}, date = {2018-03-23}, organization = {United States Department of Justice}, url = {https://www.justice.gov/usao-sdny/pr/nine-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic}, language = {English}, urldate = {2019-10-23} } Nine Iranians Charged With Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps
Silent Librarian

Credits: MISP Project