Entity: Mabna Institute
Primary attribution: Iran
Threat type: State-sponsored / state-aligned cyber espionage and intellectual-property theft
Known aliases / overlapping tracking names: Silent Librarian, TA407, COBALT DICKENS
MITRE ATT&CK Group: G0122 (Silent Librarian)
Known activity: At least 2013–present reporting
Primary targets: Universities, research organizations, government agencies, technology companies, publishers, financial organizations and other private-sector organizations
State association: Islamic Republic of Iran / Islamic Revolutionary Guard Corps (IRGC)
Sanctions: U.S. Treasury OFAC SDN designation
The Mabna Institute is an Iran-based organization publicly attributed by the U.S. government and multiple cybersecurity organizations to large-scale cyber-espionage operations. It was reportedly founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi. According to the U.S. Department of Justice, its purpose included obtaining access to foreign scientific and academic resources for Iranian universities and research organizations. Mabna subsequently employed or contracted hackers to conduct intrusions against foreign organizations.
The organization is strongly associated with the threat cluster commonly tracked as Silent Librarian, TA407, and COBALT DICKENS. MITRE specifically states that members of Silent Librarian have been affiliated with Mabna and that the group has targeted universities, government agencies and private companies since at least 2013.
The U.S. government attributes significant portions of Mabna's operations to work performed on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC). Mabna also reportedly contracted with other Iranian government and private organizations. In March 2018, the U.S. Treasury sanctioned Mabna and associated Iranian cyber actors.
The scale of the operation was considerable. The 2018 DOJ case alleged targeting of more than 100,000 professor accounts, compromise of approximately 8,000, penetration of hundreds of universities, and theft of approximately 31.5 TB of academic and intellectual-property data.
Current status note: Mabna remains on OFAC's SDN list; OFAC's current entry identifies addresses in Tehran and Zanjan, Iran.
State and Organizational Associations
The strongest documented association is with Iran.
According to DOJ allegations, Mabna specifically conducted its university spear-phishing campaign on behalf of the Islamic Revolutionary Guard Corps and contracted with Iranian governmental and private entities to conduct hacking operations.
The relationship can therefore be summarized as:
Iran → IRGC / Iranian government customers → Mabna Institute → affiliated hackers / contractors → foreign targets
Mabna also had a commercial component. Stolen academic material and compromised credentials were reportedly monetized through Iranian services including Megapaper.ir and Gigapaper.ir. Megapaper was operated by Falinoos Company, controlled by Abdollah/Vahid Karima, while Gigapaper was affiliated with Karima.
Treasury identifies Rafatnejad and Mohammadi as founding members. It specifically identifies Mirkarimi as a hacker and contractor involved in crafting/testing spear-phishing messages and organizing stolen credentials.
Behzad Mesri is sometimes included in Treasury reporting surrounding the March 2018 sanctions action. He was separately sanctioned for the HBO intrusion and should not be conflated with the nine Mabna defendants without additional evidence tying a particular operation to Mabna.
Known Attacks and Breaches
Global University Campaign — approximately 2013–2017
This is the best-documented Mabna operation.
Mabna targeted more than 100,000 professor accounts worldwide and compromised approximately 8,000 accounts. DOJ identified victims at:
- 144 universities in the United States
- 176 universities across 21 other countries
The attackers stole academic journals, theses, dissertations, books, scientific information and other intellectual property. Approximately 31.5 TB of academic information was allegedly exfiltrated to attacker-controlled infrastructure outside the United States.
The campaign generally followed a repeatable pattern:
target research → identify academics → spear-phish victim → steal credentials → access university/library resources → exfiltrate documents → deliver or sell stolen information
DOJ described this as a three-stage operation involving target research, deceptive email communications and credential theft followed by unauthorized retrieval of academic material.
Private-Sector Intrusion Campaign
Mabna also targeted at least:
36 U.S. companies and 11 companies in Germany, Italy, Switzerland, Sweden and the United Kingdom.
Affected U.S. sectors reportedly included technology, consulting, marketing, banking/investment, healthcare, biotechnology, publishing, media, legal services, industrial machinery and other industries.
Rather than relying exclusively on spear phishing, the actors frequently employed password spraying against corporate accounts. After compromise, attackers stole complete email mailboxes and sometimes created automated forwarding rules to continuously copy subsequent communications to attacker-controlled accounts.
U.S. Government Intrusions
Known targets included:
U.S. Department of Labor; Federal Energy Regulatory Commission; State of Hawaii; State of Indiana; Indiana Department of Education.
Credential theft and mailbox access were major objectives.
United Nations / UNICEF
Mabna-linked operators also targeted the United Nations and UNICEF, again focusing on credentials and email information.
Post-Indictment Operations
The 2018 U.S. indictment did not immediately stop the activity. PhishLabs reported 18 additional phishing attacks against 14 universities in five countries within approximately two weeks of the indictment. At that point it had attributed more than 780 phishing attacks against more than 300 universities in 22 countries to Silent Librarian.
Countries Associated With Mabna Operations
Sponsoring / Operating Country
Iran
Confirmed university-target countries
DOJ identified university victims in:
United States, Australia, Canada, China, Denmark, Finland, Germany, Ireland, Israel, Italy, Japan, Malaysia, Netherlands, Norway, Poland, Singapore, South Korea, Spain, Sweden, Switzerland, Turkey and United Kingdom.
Additional post-indictment phishing activity was observed against universities in France, adding it to the broader operational victim geography reported by researchers.
Known Tactics, Techniques and Procedures
Mabna/Silent Librarian operations have prominently involved:
Reconnaissance and targeting: identifying professors, researchers, employees and email addresses using open-source information.
Spear phishing: highly targeted messages impersonating legitimate academic or professional communications.
Credential phishing: cloned university, library, authentication and proxy-login portals designed to harvest usernames and passwords.
Password spraying: attempts against multiple accounts using commonly used/default passwords. The FBI warned that Mabna particularly benefited from organizations without MFA and with weak passwords.
Valid-account exploitation: compromised university and corporate credentials were subsequently used to access legitimate services.
Email collection: entire employee mailboxes were stolen in some compromises.
Email forwarding: attackers created forwarding rules allowing continued interception of incoming and outgoing mail.
Academic database exploitation: stolen credentials were used to access subscription databases, electronic libraries and university resources.
Data exfiltration: intellectual property and communications were transferred to attacker-controlled servers.
Credential/data resale: stolen academic resources and access were monetized through Iranian services.
Malware
Mabna is noteworthy because its best-documented campaigns are primarily identity- and credential-centric rather than malware-centric.
The core intrusion chain generally relies on phishing, credential harvesting, password spraying, valid accounts and abuse of legitimate university/library/email infrastructure. Therefore, domain, URL, authentication and account-behavior telemetry can be considerably more useful for historical Mabna hunting than simply searching for malware hashes.
Assessment
Attribution confidence: High.
Mabna represents a particularly well-documented example of the overlap between Iranian state requirements, contractors, hackers-for-hire and commercially motivated cyber operations. Attribution is supported by U.S. criminal indictments, Treasury sanctions, allied-government assessments and independent cybersecurity research.
The group's defining characteristic is not advanced malware but large-scale exploitation of identity. Its operators demonstrated that carefully researched phishing, cloned authentication portals, password spraying and valid credentials could produce strategic intelligence and intellectual-property gains on a massive scale.
The academic campaign alone compromised thousands of accounts and enabled the theft of tens of terabytes of research. Once credentials were acquired, legitimate university and corporate infrastructure effectively became the attackers' collection platform.
From a defensive-intelligence perspective, Mabna/Silent Librarian should therefore be hunted through a combination of historical infrastructure and behavioral indicators: suspicious authentication, impossible travel, abnormal library/database downloads, legacy authentication, repeated password-spray failures, unexpected mailbox-forwarding rules, newly registered domains mimicking institutional authentication systems and anomalous access to academic resources.
The Mabna Institute remains a U.S.-sanctioned entity.
Principal Sources
U.S. Department of Justice — Mabna Institute indictment announcement
U.S. Treasury — Mabna Institute sanctions announcement
