Iran-linked threat activity tracked as Cobalt Dickens and Silent Librarian continued targeting universities with large-scale credential-phishing campaigns designed to steal access to library systems, email, and research resources. Security researchers linked the activity to tactics associated with the Mabna Institute operators charged by the U.S. in 2018, noting that the campaign persisted despite those indictments. In one wave, attackers used 16 domains hosting more than 300 spoofed login pages impersonating 76 universities in 14 countries, including institutions in the United States, Canada, the United Kingdom, and Japan, to harvest usernames and passwords and facilitate theft of intellectual property.
Later reporting showed the university-focused phishing remained active and evolved in delivery and infrastructure. Investigators documented renewed Silent Librarian operations using recently registered domains, phishing subdomains, and IP infrastructure that mimicked legitimate academic portals, while separate campaigns in 2021 used COVID-19, Delta, and Omicron lures, malicious URLs, HTM attachments, fake Office 365 and university login pages, and in some cases spoofed Duo prompts to capture MFA credentials. Researchers also observed compromised university email accounts being reused to send additional phishing messages, underscoring a sustained effort to exploit academic institutions for credential theft, network access, and potential research and intellectual-property collection.

Get the infrastructure and lures behind it.
10 events from the most recent confirmed update back to the earliest known activity.
After the Omicron variant was announced in late November 2021, threat actors shifted from Delta-themed lures to Omicron-themed phishing messages targeting university users and harvesting credentials.
Proofpoint said it observed consistent credential-phishing campaigns against primarily North American universities beginning in October 2021, with thousands of messages sent to dozens of schools.
WHOIS data showed phishing domains tied to Silent Librarian were registered between August 14 and October 2, 2020, largely through NameCheap and privacy services.
Secureworks said the most recent domain used in the ongoing university credential-theft campaign was registered on August 19, 2018.
Secureworks reported that domains used in a new Cobalt Dickens university phishing campaign were registered between May and August 2018, indicating the group remained active after the March indictment.
On March 23, 2018, the United States indicted nine Iranian nationals allegedly tied to the Mabna Institute for hacking universities, government agencies, and businesses. U.S. authorities said the operation stole intellectual property and was conducted in support of the IRGC.
The U.S. Department of Justice said the Mabna Institute had conducted a coordinated cyber intrusion campaign since at least 2013, targeting universities, companies, and other organizations for intellectual property theft.
Malwarebytes identified 25 phishing subdomains and three IP addresses targeting 21 academic institutions worldwide, and additional analysis found 11 more suspicious subdomains and two more IPs.
CircleID reported that Silent Librarian was detected again as the academic year began in September, targeting universities and colleges to steal research data and intellectual property.
Secureworks disclosed an ongoing campaign using 16 domains and roughly 300 spoofed login pages impersonating 76 universities across 14 countries to steal credentials. The company linked the activity to Cobalt Dickens and assessed ties to earlier Iranian operations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
proofpoint.com
Open sourcecircleid.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.