Proofpoint Threat Insight Team. (2019, September 5). Threat Actor Profile: TA407, the Silent Librarian. Retrieved February 3, 2021.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.001 Domains |
GroupSilent Librarian | Silent Librarian has acquired domains to establish credential harvesting pages, often spoofing the target organization and using free top level domains .TK, .ML, .GA, .CF, and .GQ. |
| T1588.002 Tool |
GroupSilent Librarian | Silent Librarian has obtained free and publicly available tools including SingleFile and HTTrack to copy login pages of targeted organizations. |
| T1594 Search Victim-Owned Websites |
GroupSilent Librarian | Silent Librarian has searched victim's websites to identify the interests and academic areas of targeted individuals and to scrape source code, branding, and organizational contact information for phishing pages. |
| T1598.003 Spearphishing Link |
GroupSilent Librarian | Silent Librarian has used links in e-mails to direct victims to credential harvesting websites designed to appear like the targeted organization's login page. |
| T1608.005 Link Target |
GroupSilent Librarian | Silent Librarian has cloned victim organization login pages and staged them for later use in credential harvesting campaigns. Silent Librarian has also made use of a variety of URL shorteners for these staged websites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.