Madi (Mahdi) is an early Middle Eastern espionage campaign disclosed by Kaspersky and Seculert in 2012 that used low-sophistication social-engineering and the Madi infostealer to surveil hundreds of victims in Iran, Israel, and the wider region across government, critical-infrastructure, financial, and engineering sectors.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Madi was jointly disclosed by Kaspersky (Securelist) and Seculert in July 2012 after months of tracking. Named for references to 'Mahdi' in its code, the campaign is notable as one of the earliest publicly documented espionage operations concentrated on Middle Eastern victims. Attribution is deliberately uncertain and rated low-medium confidence: victims spanned both Iran and Israel, and no vendor firmly assigned a sponsor — an ambiguity preserved here rather than resolved, and the campaign has no MITRE Group ID.
The operation's tradecraft was strikingly unsophisticated, relying on extensive social engineering: spearphishing with emotionally or religiously themed lures (PowerPoint slideshows, images, and text documents with embedded executables and confusing right-to-left-override filenames) to trick users into running the Madi trojan. Once installed, Madi provided keylogging, screenshot capture, audio recording, and document exfiltration — effective collection despite its technical simplicity.
MENA is the campaign's defining theater. Kaspersky and Seculert counted more than 800 victims, primarily in Iran and Israel, with additional targets across the region — including individuals in critical-infrastructure engineering firms, government agencies, financial institutions, and academia. This cross-adversary victim set (hitting both Iranian and Israeli targets) is part of what complicates attribution.
Madi activity ceased following its 2012 public exposure and infrastructure takedown, and the campaign is assessed as retired. It is included as a foundational early-MENA espionage historical entry, explicitly flagged low-medium confidence on attribution and G-ID-less.