Silent Librarian
Also known as: TA407 · COBALT DICKENS
Overview
Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Librarian are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).
Naming & attribution
Silent Librarian is tracked under 3 names across the industry. It uses 13 documented ATT&CK techniques — more than 40% of the 174 groups tracked here. Activity attributed since at least 2013.
| Name | First reported by |
|---|---|
| TA407 | Proofpoint Threat Insight Team |
| COBALT DICKENS | Counter Threat Unit Research Team |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1589.003Employee Names — used by 3 of 174 groups -
T1608.005Link Target — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Star Blizzard Russia — 6 shared techniques (22% overlap)
- EXOTIC LILY — 4 shared techniques (17% overlap)
- HEXANE — 5 shared techniques (11% overlap)
- Sea Turtle — 4 shared techniques (11% overlap)
- Sandworm Team Russia — 8 shared techniques (10% overlap)
- Moonstone Sleet North Korea — 4 shared techniques (10% overlap)
TTPs — 13 techniques across 5 tactics
Reconnaissance
-
T1589.002Email Addresses -
T1589.003Employee Names -
T1594Search Victim-Owned Websites -
T1598.003Spearphishing Link
Resource Development
-
T1583.001Domains -
T1585.002Email Accounts -
T1588.002Tool -
T1588.004Digital Certificates -
T1608.005Link Target
Stealth
-
T1078Valid Accounts
Credential Access
-
T1110.003Password Spraying
Collection
-
T1114Email Collection -
T1114.003Email Forwarding Rule
Reporting (3)
- Silent Librarian APT right on schedule for 20/21 academic year — Malwarebytes Threat Intelligence Team
- COBALT DICKENS Goes Back to School…Again — Counter Threat Unit Research Team
- Threat Actor Profile: TA407, the Silent Librarian — Proofpoint Threat Insight Team