Cadelle is an Iran-assessed surveillance group disclosed by Symantec in 2015 alongside Chafer, that used the custom Backdoor.Cadelspy to monitor individuals — including Iranians and targets in Saudi Arabia — in an operation aligned with Iranian internal-security interests. Sourcing is thin (single primary vendor).
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Cadelle was documented by Symantec in December 2015 in the same disclosure that detailed Chafer (later APT39). Symantec assessed both as Iran-based actors, plausibly operating in the interests of the Iranian government. Confidence is low-medium and explicitly flagged: the group rests essentially on a single primary vendor report, has attracted little independent corroboration since, and has no MITRE Group ID — so its scope and boundaries are uncertain.
Cadelle's tradecraft centered on the custom Backdoor.Cadelspy, an information-stealing implant capable of logging keystrokes, capturing screenshots, stealing documents and clipboard data, recording via microphone, and monitoring removable drives — a comprehensive surveillance toolkit. Symantec noted the actor had likely been operating since around 2011, predating its public disclosure.
MENA relevance is the group's focus. Symantec observed Cadelle victims primarily among individuals and organizations in Iran and Saudi Arabia, consistent with an internal-security and regional surveillance mission (monitoring persons of interest, dissidents, and regional targets) rather than broad foreign espionage — mirroring the individual-tracking pattern of its sibling Chafer/APT39.
No distinct Cadelle activity has been reported since the 2015 Symantec disclosure, and it is assessed as retired under this name. It is included as a single-source Iranian-surveillance historical entry, explicitly flagged low-medium confidence and G-ID-less.