Actors Insights|Latest update09/05/2025
COBALT DICKENS
Named by SecureWorksSuspected state sponsor: Islamic Republic of IranAn Iranian threat group, believed to be associated with the Iranian government. They are responsible for the phishing campaigns targeting university credentials and intellectual property. They have been active since at least 2013. Known for using spoofed login pages and domains.
First Seen:Oct 2013
Last Seen:Oct 2020
Indexed Reports:2
Public IOCs:160
also known as:
COBALT DICKENS (SecureWorks)Mabna Institute (real name)TA407 (Proofpoint)TA4900 (Proofpoint)Yellow Nabu (PWC)Silent Librarian (PhishLabs)G0122 (Mitre)
Targeted Regions

AustraliaAustralia
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019

CanadaCanada
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019

ChinaChina
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018

GermanyGermany
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018

Hong KongHong Kong
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019

IsraelIsrael
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018

ItalyItaly
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018

JapanJapan
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018

NetherlandsNetherlands
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018

South AfricaSouth Africa
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018

SwitzerlandSwitzerland
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019

TurkeyTurkey
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018

United KingdomUnited Kingdom
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019

United StatesUnited States
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
Jan 2018Sep 2025
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.