National Cyber Warfare Foundation (NCWF)

CyberAv3ngers


0 user ratings
2024-06-18 15:21:23
blscott

 - archive -- 

CyberAv3ngers

MITRE:  G1027

CyberAv3ngers is a suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated APT group. The CyberAv3ngers have been known to be active since at least 2020, with disputed and false claims of critical infrastructure compromises in Israel.In 2023, the CyberAv3ngers engaged in a global targeting and hacking of the Unitronics Programmable Logic Controller (PLC) with Human-Machine Interface (HMI). This PLC can be found in multiple sectors, including water and wastewater, energy, food and beverage manufacturing, and healthcare. The most notable feature of this attack was the defacement of the devices user interface.

Strategic intelligence collection → research/IP acquisition → credential theft → commercial resale/access brokerage.

Stolen academic information was also allegedly monetized inside Iran. DOJ identifies Megapaper.ir and Gigapaper.ir as services through which stolen academic resources or access through compromised professor accounts were provided to Iranian customers.

Major Attacks and Breaches

1. Global University Espionage Campaign — 2013–2017: This remains the defining Academic Serpens operation. According to DOJ, Mabna Institute targeted more than 100,000 professor accounts worldwide. Approximately 8,000 accounts were successfully compromised across:

  • 144 U.S. universities
  • 178 foreign universities

The attackers used stolen credentials to access academic journals, theses, dissertations, electronic books, research and other proprietary academic resources. Approximately 31.5 TB of academic data and intellectual property was exfiltrated.

The 2018 case estimated that affected U.S. universities had spent approximately $3.4 billion procuring and maintaining access to the intellectual property targeted by the operation.

2. U.S. Government Compromises

Academic Serpens/Mabna Institute operations compromised employee accounts belonging to multiple government organizations. Publicly identified victims include:

  • U.S. Department of Labor
  • Federal Energy Regulatory Commission (FERC)
  • State of Hawaii
  • State of Indiana

The 2026 indictment describes at least five U.S. federal/state government agencies as victims.

3. United Nations / UNICEF

Mabna Institute also compromised accounts associated with:

United Nations

United Nations Childrens Fund (UNICEF)

These attacks expanded the groups collection beyond academia into international governmental and NGO environments.

4. Private-Sector Intrusions

The 2026 DOJ case identifies at least:

42 U.S. private-sector companies and 11 foreign companies in Germany, Italy, Switzerland, Sweden and the United Kingdom as targets/victims.

Employee email accounts and proprietary information were among the objectives.

5. HBO Compromise — 2017

The expanded 2026 indictment formally links additional Mabna Institute personnel to the well-known HBO compromise.

DOJ alleges that Behzad Mesri, together with Saeid Houshyar, Manouchehr Hashemloo, Keyvan Fayaz, Saber Shahbazi Ballojeh and Arman Kahzadian, participated in compromising HBO.

The operation resulted in theft of proprietary information followed by an attempted extortion demand of approximately $6 million in Bitcoin.

6. 2018 University Campaigns

Cybersecurity researchers continued detecting Academic Serpens/Silent Librarian operations after the March 2018 indictments.

The campaigns employed cloned university authentication and library pages. Domains were deliberately constructed to closely resemble legitimate university resources.

7. 2019 Back to School Campaign

During July–August 2019, COBALT DICKENS launched another major global university credential-harvesting operation.

Researchers identified at least 20 newly registered phishing domains targeting more than 60 universities in:

Australia, Canada, Hong Kong, Switzerland, United Kingdom and United States.

Victims received library-themed phishing messages directing them to cloned university authentication pages. Credentials submitted to the fraudulent page were stored locally and the victim was subsequently redirected to the legitimate university website.

8. 2020–2021 Academic-Year Campaign

Silent Librarian resumed operations around the beginning of the 2020–2021 academic year.

The campaign impersonated universities in Australia, Canada, Germany, Netherlands, Sweden, United Kingdom, United States and other countries. Infrastructure included Cloudflare-fronted domains and systems physically hosted in Iran.

Operational Tradecraft

Academic Serpens is primarily an identity- and credential-centric threat actor rather than a malware-heavy intrusion group.

MITRE documents the group using:

  • T1583.001 — Acquire Infrastructure: Domains: Registers domains resembling target organizations.
  • T1110.003 — Password Spraying: Uses lists of names/accounts against private-sector targets.
  • T1114 — Email Collection: Collects/exfiltrates victim mailboxes.
  • T1078 — Valid Accounts: Uses compromised credentials for unauthorized access.

Other repeatedly observed behaviors include spearphishing, cloned authentication portals, credential harvesting, university URL-shortener abuse, compromised email-account reuse, reconnaissance, target-list creation and exfiltration using attacker-controlled infrastructure.

The actor has heavily exploited free domains under .tk, .ml, .ga, .cf and .gq and has used valid TLS certificates to increase the apparent legitimacy of its phishing sites.

Targeting Profile

Primary

  • Higher education and universities

Secondary

  • Government agencies
  • Research organizations
  • Private-sector companies
  • International organizations / NGOs

Information sought

  • Scientific research
  • Engineering research
  • Medical research
  • Academic journals
  • Theses and dissertations
  • Electronic books
  • Intellectual property
  • Email
  • Authentication credentials
  • Proprietary corporate information

The campaign is unusual in its breadth: DOJ states that essentially all academic disciplines were targeted rather than one narrowly defined research area.

Threat Assessment

Attribution confidence: HIGH

The Academic Serpens → Silent Librarian → COBALT DICKENS → Mabna Institute relationship is supported by multiple independent security vendors, MITRE ATT&CK and U.S. government actions.

Iranian nexus: HIGH

The organization is based in Iran, its publicly identified members are Iranian, and both historical and current U.S. government reporting connects its operations with the IRGC and Iranian governmental/university customers.

Primary motivation: HIGH confidence — espionage/IP acquisition plus financial benefit

Academic Serpens differs from many Iranian APT clusters because strategic collection and commercial exploitation overlap. Research and credentials could benefit Iranian state and academic entities while stolen academic access was also allegedly resold.

Operational sophistication: MODERATE

Its effectiveness historically came less from advanced malware than from persistent targeting, convincing social engineering, credential reuse and exploitation of the relatively open authentication environments surrounding academic institutions.

Current activity: UNCERTAIN

Unit 42 reports a notable decrease in Academic Serpens activity after the 2020 COVID period. However, the August 18, 2026 DOJ superseding indictment dramatically expands the publicly attributed Mabna network and historical scope. The indictment should not itself be interpreted as evidence that the entire infrastructure or all 17 alleged participants remain operational today.

Intelligence Bottom Line

Academic Serpens represents one of the most consequential publicly documented Iranian operations targeting the international academic and research ecosystem. Its operational model demonstrates that access credentials themselves can constitute a strategic intelligence asset.

The most significant current intelligence development is the August 2026 identification of a 17-person alleged Mabna Institute network, expanding the original nine-person attribution and linking additional personnel to university espionage, private-sector compromises, government intrusions and the HBO operation.

For defenders, historical domains remain useful for retrospective hunting, but higher-value detections should focus on lookalike university authentication domains, anomalous library/SSO logins, password spraying, suspicious mailbox collection, unexpected forwarding rules, compromised academic accounts sending external phishing messages, and unusual downloads of large volumes of academic resources.

Primary References

 Alternate names


CyberAv3ngers is an advanced persistent threat (APT) group that has been active since at least 2015, targeting government agencies and organizations in various countries, including Russia, Ukraine, and Belarus. The groups primary focus appears to be on stealing sensitive information such as emails, documents, and passwords through spear-phishing attacks and other tactics. They have also been known to use malware like Ponybot and Dukes to gain access to their targets. CyberAv3ngers is considered a highly sophisticated threat actor with advanced technical capabilities and has been linked to the Russian governments intelligence agency, FSB.

Techniques, tactics and practices:

CyberAv3ngers is a highly sophisticated threat actor that employs a range of techniques to carry out its attacks. Some of these include spear-phishing emails, watering hole attacks, and targeted malware such as Ponybot and Dukes. They also use advanced technical capabilities, such as domain name generation algorithms (DNGC), for obfuscation. Additionally, they have been known to conduct extensive reconnaissance on their targets before launching an attack. Overall, CyberAv3ngers is a highly skilled threat actor that employs various tactics and techniques to carry out successful attacks against government agencies and organizations worldwide.



Comments
new comment
Nobody has commented yet. Will you be the first?


a.k.a
Soldiers of Soloman
TA407
Mr. Soul
Yellow Nabu
SilentLibrarian
G0122
Hydro Kitten
Mabna Institute
UNC5691
Silent Librarian
G1027
Cyber Av3ngers
Shahid Kaveh Group
APT Iran
COBALT DICKENS
Bauxite
TA4900
Dev-0118
Storm-0784
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.