Actors Insights|Latest update24/06/2025
COBALT DICKENS
Named by SecureWorksSuspected state sponsor: Islamic Republic of IranAn Iranian threat group, believed to be associated with the Iranian government. They are responsible for the phishing campaigns targeting university credentials and intellectual property. They have been active since at least 2013. Known for using spoofed login pages and domains.
First Seen:Oct 2013
Last Seen:Oct 2020
Indexed Reports:2
Public IOCs:160
also known as:
COBALT DICKENS (SecureWorks)Mabna Institute (real name)TA407 (Proofpoint)TA4900 (Proofpoint)Yellow Nabu (PWC)Silent Librarian (PhishLabs)G0122 (Mitre)
Targeted Regions
AustraliaAustralia
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
CanadaCanada
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
ChinaChina
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
GermanyGermany
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Hong KongHong Kong
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
IsraelIsrael
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
ItalyItaly
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
JapanJapan
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
NetherlandsNetherlands
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
South AfricaSouth Africa
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
SwitzerlandSwitzerland
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
TurkeyTurkey
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
United KingdomUnited Kingdom
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
United StatesUnited States
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
Jan 2018Sep 2025
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.