Silent Librarian
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Silent Librarian, also tracked as Phosphorus, is an Iranian hacker group that has been active since at least 2013 and was publicly indicted by the United States in March 2018 for a series of intrusions targeting academic institutions worldwide. The actors operate from Iran, where they have continued to conduct operations despite the indictments. Public reporting identifies them as a state‑nexiated threat actor, linking their activity to Iranian interests. The indictments alleged that the group had compromised university networks to steal research data and other proprietary information.
The group’s primary targets are universities and other higher‑education institutions, with campaigns observed in multiple regions around the globe. Their strategic objective appears to be the acquisition of intellectual property and limited‑release academic work, which they subsequently monetize by offering the stolen material through their own web portals, Megapaper.ir and Gigapaper.ir. The stolen material is typically offered for download or purchase through these portals, providing a revenue stream that sustains the group’s operations. This focus on stealing and reselling scholarly content indicates a financially motivated agenda rather than pure espionage or disruption.
Initial access is gained through phishing emails that contain URLs to look‑alike domains mimicking university portals or associated services such as library platforms, aiming to harvest login credentials. Once credentials are obtained, the actors use them to log into the legitimate university systems and exfiltrate the desired documents. Their infrastructure has evolved to host phishing sites on servers located within Iran, taking advantage of the limited cooperation between Iranian authorities and Western law enforcement to create a bulletproof hosting environment. Notable campaigns include the 2018 activity detailed in a Secureworks report, the 2019 effort spotted by Proofpoint, and the 2020 resurgence described by Malwarebytes, which highlighted the shift to Iranian‑based hosting. The group’s repeated use of the same infrastructure and tactics across years underscores a persistent operational model. This continuity allows defenders to anticipate the timing and methods of future attacks when monitoring for similar phishing lures. These operations demonstrate a recurring pattern of seasonal activity that intensifies each fall as the new academic year begins.
Incidents
Attributed incidents are available to members.
0 incidents