COBALT DICKENS
Named by SecureWorksSuspected state sponsor: Islamic Republic of IranCOBALT DICKENS is Secureworks' designation for the Iranian academic espionage cluster known as Silent Librarian and operated through the Mabna Institute front company. Active since at least 2013, the group targeted universities and research institutions across more than 22 countries using spear phishing emails impersonating library and academic resource portals to harvest faculty and student credentials. Secureworks documented continued COBALT DICKENS campaigns in 2018 and 2019, showing the group persisted with the same credential harvesting methodology even after the US DOJ indictment of nine Iranian nationals connected to the operation.
Targeted Regions
AustraliaAustralia
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
CanadaCanada
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
ChinaChina
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
GermanyGermany
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Hong KongHong Kong
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
IsraelIsrael
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
ItalyItaly
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
JapanJapan
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
NetherlandsNetherlands
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
South AfricaSouth Africa
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
SwitzerlandSwitzerland
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
TurkeyTurkey
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
United KingdomUnited Kingdom
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
United StatesUnited States
May 2018 ~ Aug 2018
May 2018 ~ Aug 2018
Jul 2019 ~ Sep 2019
Jul 2019 ~ Sep 2019
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.