Threats Feed|Chafer|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date07/12/2015

Chafer and Cadelle: Unveiling Iran's Persistent Cyber Surveillance on Middle Eastern Targets

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: SQL injection,Backdoor,Spyware,Trojan
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

Symantec researchers identified two Iran-based threat groups, Cadelle and Chafer, conducting targeted surveillance operations against individuals and organizations in Iran and across the Middle East. Active since at least July 2014, the groups deployed custom-built backdoor malware — Backdoor.Cadelspy and Backdoor.Remexi — capable of keystroke logging, audio recording, screen capture, and remote command execution. Their primary targets included telecommunications providers and airlines in the Middle East, likely to monitor the movements and communications of persons of interest. Symantec assessed that the attackers operated during Iranian business hours, and that their victim profile aligns with the intelligence interests of an Iranian state entity. Both groups were confirmed to still be active at the time of publication.

Detected Targets

TypeDescriptionConfidence
SectorInformation Technology
The sectors targeted by the attack include the airline sector, the telecommunications sector, and potentially the hosting services sector in Iran.
Verified
SectorTelecommunication
Verified
SectorTransportation
Verified
RegionAfghanistan
Verified
RegionGermany
Verified
RegionIran
Verified
RegionIraq
Verified
RegionNetherlands
Verified
RegionPakistan
Verified
RegionSaudi Arabia
Verified
RegionSingapore
Verified
RegionSudan
Verified
RegionTajikistan
Verified
RegionThailand
Verified
RegionTurkey
Verified
RegionUnited Arab Emirates
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified

Extracted IOCs

  • 37atypz123.dns-bind9[.]com
  • 5ppob16.dockerjsbin[.]com
  • 87abfg113.dockerjsbin[.]com
  • 87pqxz159.dockerjsbin[.]com
  • 0069360b20a03728665bd92c4bccf380
  • 05a88017b65754dc66f83c1d37778cc7
  • 06291777cc2840a89ce1f8f82db97453
  • 0b88451740471839755d5e46255c4bb5
  • 135b226e06a309dad5c4af1e36528f93
  • 15db41840f77723aa7e43460d9d3a5cc
  • 19cd900c135a5e9d486735ae3d2c3e97
  • 1fe84feb00e779bcdbece24ddddb38f7
  • 200e662384542ccd979d4994dd08163e
  • 2374b9655f6330b07bc3d63df399731e
  • 253e32699d5b9c4cdf8a589ef6309af5
  • 269b5a5270b34bf86c60bc793486aab7
  • 26afc6ef4315460e7e9e1cd8a3d20700
  • 27524accc1559da37deecb583419eb6e
  • 2c3ebabc800fd2256dae4a9c363e0f49
  • 2d8ba12d741fee7edae6454b06f6bc9c
  • 34b4d84d5e771d2d018d925c6ac40293
  • 38f9efa16a3b360c8ad1c872413f8dd9
  • 4387a0855c11ac9b8e8f7593eca32e6e
  • 5c0d7e787c39d64ef8546c5d2bcdab6d
  • 5c587530e0d3daca90ca26436e091d08
  • 6542d5f614ba093a43cd6a3a846d37ff
  • 6d70e287bf472663c1fbb4682d13d74a
  • 7beeb3bd4681c17fe93fffcefcd125aa
  • 894fd325751465d6f48c17106a1a91d1
  • 8a58cb79c33b196036f8d5b960316319
  • 8b9d1fc8e5864a46ba5992f7350d5d89
  • 8d26621cc8e969266985f7000536f557
  • 9aba0581781b7f5f9e57f07716a41f26
  • a437c10da3aaa8fe3241c8629c18d21a
  • ac2b52010d43632b2f66573d2550984c
  • adad23e3ca8057b562fad57a4b1c6137
  • b457ebbfbaf3d8adcce8bf8b2a7adcea
  • be303010e6ac78c7975c93aa459f2319
  • c6acff232a12259d75196a5ba6a233c7
  • d5601ec9a7d2853b68e639cf9d55b987
  • dc8fe2004c7cd048bc93c5803c001e3f
  • e40e83cdf0688e48df2cdb70962a6be2
  • f35ad22d762d59672e1977a4d96658af
  • fd2e29ad73d2e73f16667748f4536c4c
  • ff521e2a7908745fc951979e03cf0c01
  • 14a694517ca05165ca09c81c984888923a35f0b0
  • 65bb99e15e098166bff04f22805b15810f8fbf71
  • c5f1bb651f665cc30cf789ce554f2bfc9d91a19f
  • 0595979c000ef1aa3a237b0822c0556a64a75edaec8560e37e9214fd57569461
  • 0f7f0283baddacac623b0adcadf4ce146f6e61cc514abb31982299d25cd86400
  • 17a73d715333d4af746bf6d180fd129b6334a34599bf299bef48d7e27de95a68
  • 18ce17849cd25452d98b24987556322da72e1031d1c8d8680ee9fec3dfb7cb46
  • 1e5022576367f6a614afe0f8963aedd1f0c7b06502e326c43362a59ddefd118e
  • 22261e840bfaa43b982ce08a1eb18fd53400dca2a2dc6edebd1398229e5a32ee
  • 2317f2448a689aa3d4802e838ae3dfd772246e6f1eb9e262df4012a221a63825
  • 247511a37c6e01e1b4acf360003e9e72208c86df614fc711b2b152a4c3fc524f
  • 26f0d3d4eb4d445f4231157198eae01846797ce5ffc624872b0daf90736994e8
  • 27f2350d51cb41a4e5330b7cffd87ca89d263278e2a3fb8cbf0d324a4a267223
  • 2f0b3cf460b3909f259550a3a09e679d63391847ae45bd44306ddbfc1f53d5ec
  • 36f5744f72674524f56bf286dce7e4b1c93ac2859036513cfdb479daf1c014f1
  • 3db1b57303326b9fea0fbf919ae6113d013e695b2844d645bfe69d3b4bc0ec57
  • 54abd9863f185e7ebd47a3f39f99335532bd55849228a7ed29ffdab8090dc4f6
  • 6079c6ff09440faa673be55f0f7f8a613d8654e7d2cb49990db316b0add53063
  • 688dbf4cfc00957d2679dc319de0bb80f38e7b5ac4414c1543e135e37c561b8b
  • 6a88964db3e97e8176dd1df4ca69e2bfd92366a5b051d3313fa48aefa4ad288f
  • 6b8a220272382f5481e1900c1c603f67ec9d5fb45ad78bf7788dece1f20dddcd
  • 6c0d1268177ebc1ad7b8f34f04b3d38c74cf4b43e18259677759c0ef91615e24
  • 6e8f5c8addab6d875a06bc92e109c0298aede342810eb25e16d292b4fffce535
  • 82ed6493c494e88e49799c75f6b22c101c1ca3d97ac001b5487610f81d21d961
  • 8455598c9bbb0a93aa35b083ee8bb83bb01fe27cf02ee7c44052a813cb66767c
  • 90bea454ed11dbdfe0d21e097299db4354999b693489cbccc652c11cc1adce22
  • 98a9b2329eefe618daa78b6afed82cebf40cb918ad0aae7a8d7f59af4cb13b41
  • 9be5fa0e44b2fe964f292db44236ecf2d790465a9d42fe550dff20faca5a2d52
  • 9f0ac7fa30e86b4015de6f77fe219cced164f317799fdc3faaf35af730a48700
  • a8921363b0f3cca72c5487f67230b564598b2c20dcd7ea04807b7b18b78af53a
  • ac187ad5ce438cfbcd58743b2641978c2d9d000d7c30130d2df42c767be08996
  • bf24d7f4e40aaa102d8e5b048de82c6ca9ffcc6c07f207ea79d1a4af5ffc9120
  • c3a14dab06866ce635b45196022a35fe99e1d7ceccf8b378cc807249771e6e42
  • c5460b3e2b4dfe9af1c209ecd143c7f847a9092abea86275a071324110f74555
  • d6e769121d327a3f00c615459ac04bc4e2149aa17ea29479b86156298834eb62
  • d94b920a5645218d8368c1277e5d2081916e66d815c9c3e150b07ade02de970f
  • da84353f914c297878e5d5eb55a6905b655410df67b881092008b24faa90bb79
  • de529597194ed2088eb7fc246bcb698dac739c2ac3de8d7b9a5fd0e969f124fa
  • e2f430fb6f3588cd9cf63a74760e37738c91e7589df41f0bbac9a4e23b745d7e
  • ebc9d6bcd5f8e738d2ed82b1c232df06b9caf0b33ea8b4b45d7f0bfd8252a97d
  • f4db775254f4139ec677efa1a633e310189d7ad425a7f5a84fdb6ee4a3c1aa21
  • f7e44314521c04626d586e07cbab655ee59a5a0805cccef8311f669c175f5d86
  • f8fe5edcdf087368a4aa9e39d583fc80a625209f3297a4db9697d4ade6c8b9ce
  • fead15c401f0aba8e770b7a85df96852dd1b72ca367c2aef3a0913bca10da0d5
download

Tip: 89 related IOCs (0 IP, 4 domain, 0 URL, 0 email, 85 file hash) to this threat have been found.

Overlaps

ChaferIranian Chafer APT Targets Kuwait and Saudi Arabia’s Critical Sectors

Source: Bitdefender - May 2020

Detection (one case): 98a9b2329eefe618daa78b6afed82cebf40cb918ad0aae7a8d7f59af4cb13b41

OilRigStolen Code Signatures Fuel OilRig's Multi-Nation Cyber Attacks

Source: ClearSky - January 2017

Detection (one case): 87pqxz159.dockerjsbin[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions: Cadelle & Chafer Iran-Linked Surveillance Campaign

Two Iran-based cyber espionage groups, Cadelle and Chafer, were found running long-term surveillance operations against individuals and organizations in Iran and across the Middle East. They used custom-built backdoor malware — Backdoor.Cadelspy and Backdoor.Remexi — to silently spy on victims, steal data, and maintain persistent access to compromised systems for up to a year. Symantec published its findings in December 2015, confirming both groups were still active at that time.

Two distinct groups were responsible: Cadelle, which deployed Backdoor.Cadelspy, and Chafer, which operated Backdoor.Remexi and Backdoor.Remexi.B. Both are assessed to be Iran-based, based on their working hours matching Iran's business week and time zone, the use of the Solar Hijri calendar in malware file strings, and a victim profile that aligns with the intelligence interests of an Iranian state entity. Symantec noted the groups may be working for a single Iranian-aligned organization, though no shared infrastructure was confirmed.

The campaign was a targeted espionage and surveillance operation. The attackers' goal was to monitor the movements and communications of persons of interest — including dissidents, activists, researchers, and anonymous proxy users inside Iran — by compromising the services those individuals rely on, such as airlines and telecommunications providers. The malware was designed to silently collect sensitive data over extended periods rather than to cause visible disruption.

The campaign was broad in geographic reach but focused in targeting. More than a dozen organizations were compromised across the Middle East, with victims identified in Iran, Saudi Arabia, Afghanistan, and other countries in the region, as well as at least one organization in the United States. A combined total of 60 computers in a single organization were infected simultaneously for close to a year. The majority of individual victims were Iranian internet users, including those using anonymous proxy services.

The primary institutional targets were telecommunications companies and airlines in the Middle East. At the individual level, the groups focused on Iranian internet users — particularly dissidents, activists, researchers, and people using anonymous proxy services to bypass government censorship. Some compromised systems belonged to web developers and database administrators, suggesting the attackers also targeted technical staff who could provide deeper network access.

Chafer gained initial access by exploiting vulnerabilities in web servers, likely through SQL injection, to install Backdoor.Remexi. Once inside, the malware harvested credentials and enabled remote shell access, allowing the attackers to move across the network. Cadelle's Backdoor.Cadelspy arrived as a dropper that installed a persistent payload, then silently collected keystrokes, screenshots, audio recordings, clipboard contents, and printer documents — compressing everything into archives and sending them to attacker-controlled servers over HTTP.

Telecommunications providers and airlines hold vast amounts of sensitive data about individuals — call records, travel itineraries, passenger manifests, and communication metadata. For a surveillance operation focused on tracking dissidents, activists, and persons of interest, these sectors offer a shortcut: instead of targeting each individual directly, the attackers could compromise one organization and gain access to data on thousands of people. This approach is harder to detect and yields far more intelligence at scale.

Organizations should keep all server software and applications fully patched, as Chafer exploited unpatched web servers to gain initial access. Treat unsolicited emails with caution, since targeted campaigns often use malicious links and attachments. Deploy and keep updated endpoint security tools that can detect Backdoor.Cadelspy and Backdoor.Remexi. Monitor outbound network traffic for unexpected file uploads or connections to unfamiliar domains. Telecommunications, aviation, and hosting companies in the Middle East region should treat this as a high-priority threat given the attackers' demonstrated focus on these sectors.

About Affiliation
Chafer
Chafer is the name used by Symantec to track the Iranian espionage cluster widely known as APT39. Active since at least 2014, the group targets telecommunications, travel, aviation, and government organizations across the Middle East, focusing on the collection of personal information for Iranian surveillance purposes. Chafer operations are characterized by spear phishing, web shell deployment, and the use of both custom backdoors and publicly available tools such as Mimikatz and PsExec for credential theft and lateral movement. The cluster is also tracked as APT39 (Mandiant) and ITG07 (IBM).
View Chafer's Insights