Menu
Browse

Cyber Threat Actor: Silent Librarian

Aliases: 2 aliases
Actor Type Location Known Incidents
 Icon
Crime Syndicate
Iran
0 incidents
Profile

Silent Librarian, also tracked as Phosphorus, is an Iranian threat actor group that has been active since at least 2013 and focuses its operations on academic institutions worldwide. The group’s primary targets are universities and associated services such as library portals, which it seeks to compromise in order to harvest login credentials. According to publicly reported information, the stolen credentials are used to access university systems where intellectual property and limited‑release academic work, which the actors then resell through their own web sites, Megapaper.ir and Gigapaper.ir, indicating a financially motivated objective rather than pure espionage or disruption.

The group’s typical tactics involve sending phishing emails that contain links to fraudulent websites mimicking legitimate university portals or related applications. These lookalike domains are hosted on servers located in Iran, a choice noted by researchers as providing a degree of protection from takedown efforts due to limited cooperation between Iranian authorities and Western law enforcement. The phishing pages are designed to capture usernames and passwords, which are then used to gain unauthorized access to the targeted institutions. No specific malware families or custom tooling are described in the available sources, with the emphasis remaining on credential harvesting via web‑based deception.

Attribution to Iran is based on the group’s operational location and the public indictment of its members in the United States in March 2018 for a series of university‑directed intrusions spanning several years. Despite the indictment, the actors have continued to operate from Iran, mounting recurrent campaigns that typically intensify each fall ahead of the new school year. Notable publicly reported operations include a 2020 phishing wave highlighted by Malwarebytes, a 2018 campaign analyzed by Secureworks, and earlier activity observed by Proofpoint, all of which demonstrate a persistent focus on stealing and monetizing academic credentials through infrastructure hosted within Iran.

Incidents
Attributed incidents available to members
0 incidents
Sources
Sources available to members
1 source