FlagThis
← Threat Actors
/
Iran
/
Silent Librarian
DOSSIER // SILENT-LIBRARIAN
Silent Librarian
ACTIVE CAMPAIGN TRACKED
▲ High Threat
Iran
Primary Aliases:
DEV-0118
Academic Serpens
COBALT DICKENS
G0122
🔍 Adversary Rosetta Stone (9) ▾
📋 Copy All
Sponsor / State Affiliation
Government of Iran (Islamic Revolutionary Guard Corps / Mabna Institute)
Primary Motivation
Strategic Espionage and Intellectual Property Theft
Confidence Rating
95% (Grounded)
Mabna Institute Global Data Theft Campaign
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
🎯 Target Sectors & Focus
Higher Education and Research Institutions
Government Agencies
Diplomatic Organizations (e.g., United Nations)
Defense Contractors
Private Sector Intellectual Property
🛡️ MITRE ATT&CK® Attack Lifecycle
(8 TTPs)
📥 Download Navigator JSON
All Stages
8
Initial Access
4
Credential Access & Discovery
1
Command & Control
1
Operational Techniques
2
Initial Access
4
T1566
Sophisticated Spear-phishing
↗
T1566
Use of Let's Encrypt SSL certificates for phishing infrastructure
↗
T1566
Exploitation of Valid Accounts for lateral movement
↗
T1566
Strategic scraping of victim websites to customize phishing lures
↗
Credential Access & Discovery
1
T1003
Credential Harvesting
↗
Command & Control
1
T1071
Cloudflare integration to hide origin server IP addresses
↗
Operational Techniques
2
T1000
Website Cloning (using tools like HTTrack and SingleFile)
↗
T1000
URL Shortening to mask malicious destinations
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
US DOJ Indictment of Mabna Institute and IRGC for Cyber Espionage
Attacks and Vulnerabilities
2026-08-20
Adversary Rosetta Stone // Silent Librarian
×
🪟 Microsoft Threat Actor Naming
DEV-0118
📋
🛡️ Other Industry Tracking Codes
Academic Serpens
📋
COBALT DICKENS
📋
G0122
📋
Mabna Institute
📋
Mabna Institute Group
📋
TA407
📋
TA4900
📋
Yellow Nabu
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD