Silent Librarian
[Silent Librarian](https://attack.mitre.org/groups/G0122) is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of [Silent Librarian](https://attack.mitre.org/groups/G0122) are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).(Citation: DOJ Iran Indictments March 2018)(Citation: Phish Labs Silent Librarian)(Citation: Malwarebytes Silent Librarian October 2020)
Properties
- stix_id
- intrusion-set--90784c1e-4aba-40eb-9adf-7556235e6384
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (13)
Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They incl
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresse
Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with email providers to further their op
Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email
Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information
Adversaries may setup email forwarding rules to collect sensitive information. Adversaries may abuse email forwarding rules to monitor the activities
Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email addresses as well as to help guide oth
Adversaries may put in place resources that are referenced by a link that can be used during targeting. An adversary may rely upon a user clicking a m
Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials.
Adversaries may search websites owned by the victim for information that can be used during targeting. Victim-owned websites may contain a variety of
Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A to
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense
Explore this actor's full graph with Ninja Signal