Cadelspy

S0454

Malware.View on attack.mitre.org

About this malware

Cadelspy is a backdoor that has been used by APT39.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1010
Application Window Discovery

Cadelspy has the ability to identify open windows on the compromised host.

T1056.001
Keylogging

Cadelspy has the ability to log keystrokes on the compromised host.

T1082
System Information Discovery

Cadelspy has the ability to discover information about the compromised host.

T1113
Screen Capture

Cadelspy has the ability to capture screenshots and webcam photos.

T1115
Clipboard Data

Cadelspy has the ability to steal data from the clipboard.

T1120
Peripheral Device Discovery

Cadelspy has the ability to steal information about printers and the documents sent to printers.

T1123
Audio Capture

Cadelspy has the ability to record audio from the compromised host.

T1560
Archive Collected Data

Cadelspy has the ability to compress stolen data into a .cab file.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Chafer Dec 2015 Open source
    Symantec Security Response. (2015, December 7). Iran-based attackers use back door threats to spy on Middle Eastern targets. Retrieved April 17, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.