Cadelle is a small threat actor group conducting long-term cyber espionage operations since at least 2011.
Analyst brief
Cadelle is a threat actor group estimated to consist of 5 to 10 individuals, with activity potentially dating back to at least 2011 based on C&C registrant information. Their origin is unknown but may be linked to IR (Iran), and they are associated with long-term cyber espionage operations, though specific victim sectors are not detailed in the provided data. They employ custom C2 infrastructure and TTPs that have likely evolved since 2014, with early indicators found in executable compilation times from 2012. Defenders should prioritize hunting for historical indicators tied to their early C&C registrant patterns, monitor for persistent low-profile activity, and remain vigilant against small, dedicated teams using slowly updated toolsets.
Cadelle
unknown
Symantec telemetry identified Cadelle and Chafer activity dating from as far back as July 2014, however, it’s likely that activity began well before this date. Command-and-control (C&C) registrant information points to activity possibly as early as 2011, while executable compilation times suggest early 2012. Their attacks continue to the present day. Symantec estimates that each team is made up of between 5 and 10 people.
What early indicators exist regarding the start date of the Cadelle group's activity?+
Although Cadelle activity has been observed since July 2014, C&C registrant information points to activity possibly as early as 2011. Additionally, executable compilation times suggest early 2012.
Based on Symantec's estimates, what kind of threat actor is Cadelle in terms of operational scale?+
Cadelle is a threat actor operating in small teams, with each team estimated to consist of between 5 and 10 people.