Threat actor · all actors
Silent LibrarianG0122 state
🇮🇷 IR
aka Silent Librarian, TA407, COBALT DICKENS, Mabna Institute, TA4900, Yellow Nabu, Mabna Institute Group
Last updated: 2026-08-20
About this actor
Last Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute. According to prosecutors, the defendants stole more than 31 terabytes of data from universities, companies, and government agencies around the world. The cost to the universities alone reportedly amounted to approximately $3.4 billion. The information stolen from these universities was used by the Islamic Revolutionary Guard Corps (IRGC) or sold for profit inside Iran. PhishLabs has been tracking this same threat group since late-2017, designating them Silent Librarian. Since discovery, we have been working with the FBI, ISAC partners, and other international law enforcement agencies to help understand and mitigate these attacks.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Secureworkscolour-metal names
ProofpointTA threat-actor id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 20 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1078Valid Accounts ↗T1110Brute Force ↗T1110.003Password Spraying ↗T1114Email Collection ↗T1114.003Email Forwarding Rule ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1585Establish Accounts ↗T1585.002Email Accounts ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.004Digital Certificates ↗T1589Gather Victim Identity Information ↗T1589.002Email Addresses ↗T1589.003Employee Names ↗T1594Search Victim-Owned Websites ↗T1598Phishing for Information ↗T1598.003Spearphishing Link ↗T1608Stage Capabilities ↗T1608.005Link Target ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-6 | 7 / 20 | 35% |
SI-4 | 7 / 20 | 35% |
CA-7 | 5 / 20 | 25% |
CM-2 | 5 / 20 | 25% |
SC-7 | 5 / 20 | 25% |
AC-20 | 4 / 20 | 20% |
AC-3 | 4 / 20 | 20% |
AC-4 | 4 / 20 | 20% |
IA-2 | 4 / 20 | 20% |
IA-5 | 4 / 20 | 20% |
AC-2 | 3 / 20 | 15% |
AC-5 | 3 / 20 | 15% |
AC-6 | 3 / 20 | 15% |
AC-16 | 2 / 20 | 10% |
AC-17 | 2 / 20 | 10% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Star Blizzard 0.34
- EXOTIC LILY 0.24
- Salesforce Data Exfiltration 0.21
- FunnyDream 0.18
- HEXANE 0.18
Same nation-state
- HomeLand Justice 1.00
- Outer Space 1.00
- Juicy Mix 1.00
- Cleaver 1.00
- OilRig 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00