Shadow Academy

Description

(RiskIQ) In early July 2020, RiskIQ began tracking a phishing campaign identified through our internet intelligence graph targeting colleges and universities worldwide. From July 2020 into October 2020, RiskIQ systems uncovered 20 unique targets in Australia, Afghanistan, the UK, and the USA.

All these attacks used similar tactics, techniques, and procedures (TTPs) as Mabna Institute, Cobalt Dickens, Silent Librarian, an Iranian company that, according to the FBI, was created for illegally gaining access ‘to non-Iranian scientific resources through computer intrusions.’ Mabna Institute earned the moniker ‘Silent Librarian’ due to its focused efforts to compromise university students and faculty by impersonating university library resources using domain shadowing to harvest credentials.

However, while RiskIQ’s findings are consistent with TTPs in use by Silent Librarian, they alone are not sufficient to attribute the threat activity we’ve detected against these 20 universities directly to Mabna Institute. Therefore, RiskIQ has named actors identified during this research as ‘Shadow Academy.‘

Names

NameName-Giver
Shadow AcademyRiskIQ

Country

Motivation

  • Information theft and espionage

First Seen

2020

Observed Sectors

Observed Countries

Information

Other Information

Uuid

291f5c4f-f25f-4a84-824a-0dc010179887

Last Card Change

2021-01-06