Cadelspy

MITRE ATT&CK: S0454 View on attack.mitre.org

Aliases: Cadelle, Cadelspy

First seen
2014-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-08-05 00:30:45
Profile updated
2026-07-07 12:49:54

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:ir country_code:us

Context

Cadelspy is a backdoor that has been used by APT39.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Cadelspy (S0454). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-06-04_bedab9fb22e8edcadd157531bd7ddfef_cadelspy_glassworm_ngrbot_qilin_stealc 2026-08-05 1

Detection coverage

  • 2 YARA rules
  • 61 Sigma rules

Malware & tools used

  • Application Window Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Audio Capture (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Cadelspy_Auto (yara-rule)
  • ARKBIRD_SOLG_MAL_Cadelspy_Stealer_May_2021_1 (yara-rule)

Reports & references

  • Broadcom/Symantec — Iran Based Attackers Use Back Door Threats Spy Middle Eastern Targets (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cadelspy (report)
  • web.archive.org — Iran Based Attackers Use Back Door Threats Spy Middle Eastern Targets (report)
  • Broadcom/Symantec — Cadelspy Remexi Ioc (report)
  • MITRE ATT&CK — S0454 (report)

External references