Cadelle

First seen
2011-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:52:23

Targeted industries: government-and-public-sector energy-and-utilities transportation-and-logistics

Targeted regions: country_code:sa country_code:ae country_code:tr

Context

Symantec telemetry identified Cadelle and Chafer activity dating from as far back as July 2014, however, it’s likely that activity began well before this date. Command-and-control (C&C) registrant information points to activity possibly as early as 2011, while executable compilation times suggest early 2012. Their attacks continue to the present day. Symantec estimates that each team is made up of between 5 and 10 people.

Reports & references

  • Broadcom/Symantec — Iran Based Attackers Use Back Door Threats Spy Middle Eastern Targets (report)

External references