Actors Insights|Latest update27/01/2025
COBALT DICKENS
Named by SecureWorksSuspected state sponsor: Islamic Republic of IranAn Iranian threat group, believed to be associated with the Iranian government. They are responsible for the phishing campaigns targeting university credentials and intellectual property. They have been active since at least 2013. Known for using spoofed login pages and domains.
First Seen:May 2018
Last Seen:Sep 2019
Indexed Reports:2
Public IOCs:160
also known as:
G0122 (Mitre)Mabna Institute (real name)Silent Librarian (PhishLabs)TA407 (Proofpoint)TA4900 (Proofpoint)Yellow Nabu (PWC)
Targeted Regions
AU
AustraliaAustralia
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
CA
CanadaCanada
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
CN
ChinaChina
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
DE
GermanyGermany
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
HK
Hong KongHong Kong
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
IL
IsraelIsrael
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
IT
ItalyItaly
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
JP
JapanJapan
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
NL
NetherlandsNetherlands
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
ZA
South AfricaSouth Africa
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
CH
SwitzerlandSwitzerland
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
TR
TurkeyTurkey
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
GB
United KingdomUnited Kingdom
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
US
United StatesUnited States
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
Jan 2018Sep 2025
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.