Threat Actor Profile Silent Librarian
Silent Librarian is an Iranian-based Advanced Persistent Threat (APT) actor that focuses on information theft in primarily Western states. The first observation of activity by the group dates back to 2013. During this campaign, they were observed to have stolen data from universities and the private sector. Their later campaigns mainly targeted universities, aiming to steal information. The attacks of Silent Librarian are characterized by sophisticated spear phishing attacks against individuals of their targeted organizations.
- Aliases: COBALT DICKENS, Mabna Institute, TA407, Silent Librarian, Yellow Nabu, TA4900
- Strategic motives: Information theft, Espionage
- Affiliation: Iran - Islamic Revolutionary Guard Corps (IRGC)
- Cyber capabilities: ★★☆☆☆
- Target sectors: Education, Government, Private sector
- Observed countries: Australia, Canada, China, Denmark, Germany, Hong Kong, Ireland, Israel, Italy, Japan, Malaysia, Netherlands, Norway, Poland, Republic of Korea, Singapore, South Africa, Spain, Sweden, Switzerland, Turkey, UNICEF, United Kingdom, United Nations, United States
Request a free membership to access our full research insights
Already a member? Login here
Origins, Motivations & Targets
Attribution
It can be stated with a high degree of confidence that Silent Librarian operates on behalf of the Iranian government. This assessment is based on research of various sources providing evidence regarding the sponsorship of Silent Librarian’s operations. According to the news site and think tank Council on Foreign Relations, Silent Librarian operates on behalf of the Mabna Institute[1], which is an Iran-based private company acting in service of the Islamic Revolutionary Guard Corps (IRGC) to steal credentials and intellectual property for private financial gain and to be used by the IRGC[2] [3].
Strategic motivations
Silent Librarian’s main strategic motivations are information theft and economic espionage[4]. The group mainly targets educational institutions to acquire intellectual property. It appears that Silent Librarian does not focus on specific academic disciplines, but rather operates on an opportunistic basis and steals the information that they manage to access[5].
Hunt & Hackett’s research indicates that the focus on the academic sector is linked to sanctions related to technology and other goods in Iran. Western sanctions on Iran affect their scientific community. For example, cutting them from the international financial system makes it harder for individuals to subscribe to international academic journals. Importing western technologies is also restricted[6]. These restrictions set a motivation for Iran to get their hands on this knowledge or technologies in other ways.
Silent Librarian was previously observed selling their stolen data on an Iranian website named Megapaper[.]ir, as well as selling access to compromised accounts via another Iranian website called Gigapaper[.]ir[7]. This indicates that they might also pursue financial gain.
Target selection
During their campaigns, Silent Librarian most often focuses on information theft or credential theft from individuals working for organizations that possess data that is potentially valuable for the group. Among the victimized institutions were many universities, being by far the most prevalent victimized organization type and therefore making the educational sector Silent Librarian’s primary target. However, in their earlier campaigns some private and government sectors were also targeted[8]. Apart from an interview in 2017 with Crane Hassold (Director of Threat Intelligence at Phishlabs at that time) in the Washington Post, in which a focus on three specific sectors is mentioned[9], there are no indications that Silent Librarian focuses on specific knowledge areas. This is different from some actor groups from other nations that often demonstrate a clear interest in specific knowledge areas that align with the countries’ strategic agenda.
As to the private organizations targeted in the earliest campaigns of Silent Librarian, there is no publicly available information confirming their identities. However, Iran’s targets for commercial espionage typically fall into categories that relate to their commodities industry and military technological capabilities[10], which indicates a possibility that these sectors were targeted by Silent Librarian as well.
Although no specific geographical pattern or profile with regards to the victimized institutions can be found, it is notable that a large proportion of the attacks occurred in Western countries. Among the reported incidents with Silent Librarian, the prevalence of victimized organizations (mainly universities) within the US is highly over-represented, compared to other countries. Next up are European countries, which are highly represented in the list of victims as well. This indicates a particular interest of the threat actor in American and European knowledge institutions. A likely explanation for this is that Western sanctions on Iran restrict access to resources, including research and technology, which consequently leads to Iranian forces attempting to, and often succeeding at, stealing otherwise restricted information. For organizations to determine their targetability by Silent Librarian, they should consider the attractiveness of their research assets.
SWOT analysis
Strengths, weaknesses, opportunities & threats
Strengths
- IRCQ-backed & undeterred by criminal prosecution
- Sophisticated phishing campaigns with specific themes for each campaign
- Short attacking spans and limited direct impact on targets might hold victims back from rigorous investigations
- Relatively short time span of the attacks, so limited time for defenders to detect and respond against them
Weaknesses
- Target selection within the educational sector appears to be random and opportunistic
- Reliant on social engineering
- Unable to conduct long-term espionage activities
Opportunities
- Ongoing geopolitical conflicts in the Middle East
- Social engineering remains an attractive attacking vector because it abuses human nature
- Educational institutions have thousands of end users
Threats
- Increased attention on Iranian activity in general
- Protective controls such as MFA will have protective value
- Western states implementing legislation on mandated cybersecurity protections, applicable to educational institutions: often require MFA
- International sanctions
Campaigns Overview
January 1, 2022
16:00 PM
Targeting universities, companies and governmental entities
2013 - 2017
In 2018, a US Department of Justice (DOJ) indictment was filed against nine Iranian hackers who had operated for Silent Librarian. According to the indictment, during the campaign that ran from 2013 until at least December 2017 more than 140 US universities, 30 US companies and five US government agencies were compromised by this threat actor. Furthermore, 176 other universities in 21 foreign countries were compromised. All academic disciplines were targeted[12].
During this period, Silent Librarian demonstrated their capacity to deploy sophisticated phishing campaigns. Their phishing emails were contextually accurate, appeared authentic, and they were grammatically correct[13]. Furthermore, their credential harvesting pages were almost identical to the legitimate pages. According to Phishlabs, Silent Librarian kept their phishing consistent over the course of this campaign[14].
January 1, 2022
16:00 PM
Undeterred Librarians
2018
After the March 2018 indictments, Silent Librarian did not slow down and kept targeting universities worldwide. Between May and August 2018, the group was building their infrastructure by registering domain names. These domain registrations indicate that the March 2018 indictments did not have a significant deterring effect on them. With this campaign, the group was observed targeting at least 76 universities located in 14 countries[15].
Then in August 2018, Silent Librarian was found to be spoofing login pages for university libraries across the world[16]. Although there is no evidence available on the delivery method of the spoofed websites for this campaign, the extensive usage of sophisticated phishing during previous campaigns make it likely that in their 2018 campaign, they also used phishing to persuade university students or employees to visit and log in to the spoofed websites[17].
January 1, 2022
16:00 PM
The library needs to be stocked
2019
In 2019, Proofpoint reported a new phishing campaign by Silent Librarian, targeting universities between June 2019 and October 2019[18]. According to New Jersey Cybersecurity & Communications Integration Cell, the campaign was focused on stealing intellectual property from universities[19].
The phishing e-mails that were sent during the campaign contained details about university library accounts. This modus operandi was similar to their 2018 campaign; a specific example is an e-mail in which the recipient was asked to click on an embedded link because of the expiration of their university library account. The link then lead to a spoofed website, asking for credentials. Silent Librarian leveraged external events, such as publicized weather and downtime alerts to enhance the email’s credibility (see Figure 1). They also used compromised university e-mail accounts to send phishing e-mails to other universities, further ensuring their effectiveness. From a resource and infrastructure perspective, it was found that the group uses URL shorteners[20], which makes it more difficult to detect the malicious e-mails.

Figure 1. Malicious university login portal, containing an accurate weather downtime alert | Source: Proofpoint.
.
January 1, 2022
16:00 PM
The Librarian’s attempt to expand
2020
Throughout 2020, threat intelligence company Recorded Future reported an increase in the pace of operational activity by the threat actor[22]. Their report also states that Silent Librarian’s TTPs remained mostly unchanged within this time period.
The group was active mostly during the start of the academic year of 2020-2021, according to Malwarebytes. They observed activity of this campaign since at least mid-September 2020. This campaign entailed similar TTPs as seen during previous campaigns. A noteworthy technique during this campaign was the swapping of top-level domain names in order to make their phishing websites appear legitimate[23]. This is done by registering domain names that are very similar or identical to the original domain, except for the top level domain name (.nl/.com/.org), which is changed.
This campaign was different from previous campaigns due to an external factor: COVID-19. Students and staff worked remotely which in turn increased their engagement with digital platforms and therefore made successful phishing emails more likely.
January 1, 2022
16:00 PM
Operating in silence?
2021 - 2023
Since the last campaign in 2020, no large clusters of activity of the threat actor have been observed. This does not directly indicate that their campaigns have stopped altogether, rather it is possible that they have adapted their TTPs, attempting to operate more under the radar. There is one observation by Recorded Future, according to which network communications between known infrastructure of Silent Librarian and academic institutions in Spain and Switzerland were detected between February and March 2021 [24].
January 1, 2022
16:00 PM
Campaigns summary
Silent Librarian has been actively targeting organizations since 2013 until at least 2021. Over the past decade, Silent Librarian victimized hundreds of universities worldwide, and numerous private companies and government sector organizations.
Noteworthy is the timing of Silent Librarian’s attacks against universities; they tend to time their operations during the summer and the beginning of an academic year. They likely try to take advantage of the chaos of the new academic year during this period[25]. During these campaigns, a recurring feature was (library themed) phishing attacks on universities worldwide.
Connection to other actors
Between July and October 2020, RiskIQ observed a phishing campaign very similar to those conducted by Silent Librarian[45]. There is no certainty about the link with Silent Librarian; the similarities that were found are not enough to attribute.
The observed campaign targeted at least 20 knowledge institutions (colleges and universities) in Australia, Afghanistan, the United Kingdom and the United States. RiskIQ assumes that the threat actor timed their campaign so that they could ‘take advantage of the back to school chaos’[46]. Silent Librarian is also known for their use of this strategy[47]. The Shadow Academy campaign aimed to steal credentials. Their objective with the credentials remains unclear, but it is likely that they wanted to steal information. Their phishing e-mails covered a variety of themes, with 37% of them being university library impersonations (just like Silent Librarian). The others were 63% student portal-related and 11% financial aid-themed[48].
This threat actor was only mentioned once by RiskIQ in relation to this campaign. The TTPs used by this threat actor are similar to those of Silent Librarian, including corresponding phishing themes. Furthermore, the group uses similar timing (beginning of academic year) as Silent Librarian, and they victimize similar organizations (educational institutions). However, no evidence of overlap in infrastructure was found. No evidence with regards to their strategic objectives is publicly available, meaning we are only in a position to make assumptions. These can therefore not be used in attribution to Silent Librarian. It is, however, very well possible that Shadow Academy is in some way related to Silent Librarian, most likely by both of them being connected to the Mabna Institute.
Silent Librarian in the Netherlands
Dutch universities are not spared in Silent Librarian’s campaigns; several Dutch Universities are confirmed to have been targeted by Silent Librarian during their past campaigns, mainly in 2020. Utrecht University is mentioned in a list of Silent Librarian targets in 2020 by Malwarebytes. A list composed by Alienvault in 2019 of spoofed domains by Silent Librarian contains domains that seemingly spoof Leiden University, Utrecht University, and Twente University. According to the available data, Utrecht University and University of Twente seem to be their most targeted educational institutions within the Netherlands. Seemingly spoofed domains of University of Amsterdam, Utrecht University and University of Twente are included in a list that is related to Shadow Academy.
The University of Twente reported in 2020 that they were actively being targeted by Silent Librarian at that time. The domain they provided in a screenshot is identical to a spoofed domain that RiskIQ assessed to belong to Shadow Academy[56]. This could either indicate that Shadow Academy and Silent Librarian are related or identical, or that UT’s attribution to Silent Librarian actually should be attribution to Shadow Academy. Because the indications that are mentioned by UT are not disclosed, the relationship between the targeting of UT and the attribution to Silent Librarian or Shadow Academy remains unknown.
Trends
The TTPs of this actor typically abuse valid accounts by logging in with obtained credentials through phishing or brute force. MFA is a mitigation which has been proven effective against these types of initial access techniques and has been implemented by many organizations since 2019. As the US Cybersecurity & Infrastructure Security Agency points out, One-Time Password MFA and Mobile Push notifications with number matching are still vulnerable to phishing attacks. However circumventing MFA still requires additional attacking steps, which might change the cost-benefit balance of the usage of these techniques. The campaigns of Silent Librarian appear to have caught the attention of universities, especially around 2020. After 2020 one attribution to Silent Librarian was publicly available and one vendor noticed limited activity by the group. However, details about this campaign were not disclosed.
The international sanctions on Iran have not been lifted since the group’s last large-scale campaigns in 2020. This is therefore not considered a reason for the discontinuation of their operations. With several geopolitical developments in the Middle East and related to Iran, it might be possible that Iran has shifted its focus to more pressing events, but the exact reasons behind why almost no new observations of Silent Librarian were made after 2020, are still unknown.
Conclusion
To summarize, Silent Librarian is an Iranian advanced persistent threat actor that operates on behalf of the Mabna Institute, which is linked to the Iranian government. Their primary target is the educational sector with universities being the main victims, presumably as an attempt to counterbalance Western sanctions against Iran. In the group’s early days they also targeted the private and governmental sector.
Silent Librarian steals information and sells compromised accounts that have access to information. Their attacks typically have a short time span as they do not attempt to persist for a longer period of time in a network. The threat actor has sophisticated capabilities in deploying spear phishing campaigns, similar to other Iranian APTs.
The last observed activity of the threat actor dates back to a single event in 2021. It is unknown whether Silent Librarian still operates or not. In 2020, there was an observation of another Iranian actor that is very similar to Silent Librarian. There are no indications that the group has stopped, but there are also limited indications that the group has continued their attacks. Therefore, Silent Librarian is still considered a threat to the confidentiality of the information of universities worldwide.
Sources
1. https://www.cfr.org/cyber-operations/search?keys=Silent+Librarian
2. https://home.treasury.gov/news/press-releases/sm0332; https://www.spiegel.de/lebenundlernen/uni/iranische-hacker-attackieren-23-hochschulen-in-deutschland-a-1203973.html
4. https://www.cfr.org/cyber-operations/indictment-officials-mabna-institute
5. https://www.fbi.gov/news/stories/nine-iranians-charged-in-hacking-scheme-032318
6. https://www.rochester.edu/orpa/compliance/export/ofac/page_03.html
8. https://www.cfr.org/cyber-operations/indictment-officials-mabna-institute
10. *Iran_Cyber_Final_Full_v2.pdf (carnegieendowment.org)
15. https://www.secureworks.com/blog/back-to-school-cobalt-dickens-targets-universities
16. https://www.secureworks.com/blog/back-to-school-cobalt-dickens-targets-universities
17. https://www.secureworks.com/blog/cobalt-dickens-goes-back-to-school-again
18. https://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-ta407-silent-librarian
20. https://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-ta407-silent-librarian
21. https://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-ta407-silent-librarian
22. https://go.recordedfuture.com/hubfs/reports/cta-2021-0421.pdf
23. https://www.malwarebytes.com/blog/news/2020/10/silent-librarian-apt-phishing-attack
24. https://go.recordedfuture.com/hubfs/reports/cta-2021-0421.pdf
25. https://community.riskiq.com/article/44eb0802/description
26. https://www.huntandhackett.com/threats/iran
27. https://www.secureworks.com/blog/cobalt-dickens-goes-back-to-school-again
28. https://www.justice.gov/usao-sdny/press-release/file/1045781/download
29. https://www.httrack.com/page/1/en/index.html
30. https://chromewebstore.google.com/detail/singlefile/mpiodijhokgodhhofbcjdecpffjipkle
31. https://attack.mitre.org/groups/G0122/
32. https://attack.mitre.org/datasources/DS0015/
33. https://attack.mitre.org/datasources/DS0038/
34. https://attack.mitre.org/techniques/T1078/
35. https://attack.mitre.org/datasources/DS0028/
36. https://attack.mitre.org/techniques/T1078/
37. https://attack.mitre.org/datasources/DS0002/#User%20Account%20Authentication
38. https://attack.mitre.org/datasources/DS0002/#User%20Account%20Authentication
39. https://attack.mitre.org/datasources/DS0029/
40. https://attack.mitre.org/datasources/DS0029/
41. https://attack.mitre.org/datasources/DS0029/
42. https://attack.mitre.org/datasources/DS0029/#Network%20Connection%20Creation
43. https://attack.mitre.org/datasources/DS0035/
44. https://attack.mitre.org/datasources/DS0002/#User%20Account%20Authentication
46. https://csirt.cd.mil.gr/phishing-campaign-targeted-universities-worldwide/
48. https://www.itpro.com/security/hacking/358001/20-universities-targeted-by-shadow-academy-hackers
49. https://www.malwarebytes.com/blog/news/2020/10/silent-librarian-apt-phishing-attack
50. https://www.utwente.nl/en/cyber-safety/news/2020/2/289137/new-phishing-attack-aimed-at-students
51. https://www.wur.nl/en/newsarticle/Beware-of-phishing-e-mails-think-before-you-click.htm
52. https://www.malwarebytes.com/blog/news/2020/10/silent-librarian-apt-phishing-attack
53. https://otx.alienvault.com/pulse/5da4a7ab756627fcce84efcc/
54. https://community.riskiq.com/article/44eb0802/description
55. https://www.utwente.nl/en/cyber-safety/news/2020/2/289137/new-phishing-attack-aimed-at-students
56. https://community.riskiq.com/article/44eb0802/description
57. https://www.okta.com/resources/whitepaper-the-secure-sign-in-trends-report/thankyou/
59. https://wp.nyu.edu/itsecurity/2020/02/11/new-silent-librarian-phishing-scam-alert/
60. https://kb.oakland.edu/uts/PhishTank_FreshPhish
61. https://www.infosecurity-magazine.com/news/iranian-apt-group-targets-global/
Sint oratio at per, diam saepe dicam ei sea. At civibus appetere cum, quem habeo in. Eam modo apeirian te, ut altera iisque evertitur sit. Cu saperet inermis aliquando nam, per impetus qualisque interesset ex, vix at omittantur instructior disputationi.
