Silent Librarian, also known as Cobalt Dickens and associated with the Mabna Institute, is an Iranian threat actor active since at least 2013 that has primarily targeted universities and higher education institutions worldwide. The group has been linked in public reporting to Iranian state interests and has also been described as financially motivated, with operations focused on stealing academic research, intellectual property, and access to subscription-based scholarly resources. The actor is best known for highly tailored spearphishing campaigns that impersonate university library administration and academic login portals. Its operations commonly use cloned university web pages, stolen institutional branding, spoofed lookalike domains, and low-volume but personalized phishing emails themed around library access, overdue materials, or account renewal. Silent Librarian has repeatedly targeted students, faculty, and university staff, then used harvested credentials to gain unauthorized access to online accounts and academic resources. The group has also used password spraying against private-sector targets and has established attacker-controlled email accounts to receive mail forwarded from compromised accounts. Operationally, Silent Librarian demonstrates strong capability in credential theft and session abuse through phishing infrastructure built around spoofed domains and cloned authentication pages. The actor has used compromised accounts at one institution to pivot into phishing users at other institutions, abused URL shorteners and legitimate services to obscure redirection chains, and adapted lures to current events and changes in target portals. Public reporting has tied the group to campaigns affecting universities across North America, Europe, the Middle East, Asia, and Oceania, with especially persistent targeting of U.S. and other Western academic institutions. Related reporting also attributes broader sector targeting under the Cobalt Dickens name, including construction, media, health care, and transportation. Silent Librarian is widely associated with large-scale theft of academic data and intellectual property. Public indictments and security reporting have connected members or affiliates to the Mabna Institute and alleged support to the Islamic Revolutionary Guard Corps. The actor’s activity has continued despite law-enforcement action, indicating durable operational capacity and sustained interest in academia-focused credential harvesting and data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
100 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for a Linux usermod root UID set analytic; no specific campaign or activity is described in this reference.
Listed as a threat actor associated with Azure Active Directory account takeover, persistence, privilege escalation, and related cloud-focused post-compromise activity detected via PowerShell module installation.
Listed as a threat actor associated with the Valid Accounts technique in the context of AWS SAML provider update detection and potential federated credential abuse.
Listed as a threat actor associated with the detection's ATT&CK-style annotations for valid accounts and alternate authentication material activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.