Aliases: disponibles, ITG07, Rana, APT39, Remix Kitten, G0087, Remexi, entre otros, este grupo se destaca por su uso de herramientas, técnicas avanzadas en ataques cibernéticos
Cadelle is a state-sponsored cyber threat actor first documented as early as 2011, though Symantec telemetry observed activity from July 2014, with attacks continuing as of their 2015 reporting. The group is assessed with high confidence to be of Iranian origin, primarily motivated by information theft and espionage targeting governmental and private sectors. Cadelle distinguishes itself by deploying complex malware campaigns utilizing custom backdoors like Backdoor.Cadelspy, advanced phishing techniques, zero-day vulnerabilities, high operational security, and obfuscation to avoid detection. While often discussed alongside the related, but distinct, Chafer group, Cadelle operates independently in its cyber espionage efforts.