FORENSIA

THREAT_ACTOR · G0122

Silent Librarian

Also known as: Silent Librarian, TA407, COBALT DICKENS

Profile

Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Librarian are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).

MITRE ATT&CK ↗

Techniques

13 ATT&CK techniques attributed to this actor.

Related corpus activity

2,052 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Silent Librarian.

IndicatorTypeFamilySevSrc
cve-2026-4368cveransomware851
cve-2024-1781cve851
cve-2025-23304cve852
cve-2017-17215cve852
cve-2026-22584cve852
cve-2025-68670cve852
cve-2018-8007cve851
cve-2016-0638cvephishing851
cve-2025-66478cve852
cve-2025-0921cve852
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
f1551d3e5d144eef4e70a29dd3dc52fb22459d1fhash802
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385achash802
2654c08491a0f7c4a3dfc6282de5638bhash803
625b6535321d58bb5c613e85332bf731hash803
681075027553546c119ec447eb8df84633dcffcehash803
873f1277a42de5c82f869459e7fb7c94554a642bhash803
52fda5c1b9704544f32ee98d9060e689hashransomware802
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
123e80a34508c4dede7cc70e76931fcchash803
b8eed63ab9cbdca494f26a6f66bfd4a0a693b3f0hash803
01e3dce00ea45829bd9f6a583004976ac63973a0hashcryptojacking801

Showing the top 30 by severity of 2,052.