Cadelspy

Cadelspy is a backdoor that has been used by APT39.[1]

ID: S0454
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 22 May 2020
Last Modified: 29 May 2020

Techniques Used

Domain ID Name Use
Enterprise T1115 剪贴板数据

Cadelspy has the ability to steal data from the clipboard.[1]

Enterprise T1120 外围设备发现

Cadelspy has the ability to steal information about printers and the documents sent to printers.[1]

Enterprise T1113 屏幕捕获

Cadelspy has the ability to capture screenshots and webcam photos.[1]

Enterprise T1010 应用窗口发现

Cadelspy has the ability to identify open windows on the compromised host.[1]

Enterprise T1560 归档收集数据

Cadelspy has the ability to compress stolen data into a .cab file.[1]

Enterprise T1082 系统信息发现

Cadelspy has the ability to discover information about the compromised host.[1]

Enterprise T1056 .001 输入捕获: Keylogging

Cadelspy has the ability to log keystrokes on the compromised host.[1]

Enterprise T1123 音频捕获

Cadelspy has the ability to record audio from the compromised host.[1]

Groups That Use This Software

ID Name References
G0087 APT39

[1]

References