More about the Madi campaign, its targets, techniques and tools involved
An unusual number of religious and political ‘distraction’ documents and images were dropped when the initial infection occurred.
Some artifacts and the location of the victims suggested Iranian origins. The attackers were no doubt fluent in Persian - strings written in this language are littered throughout the malware and the C&C tools.
A campaign from 2011 to 2013 to infiltrate computer systems throughout the Middle East, with a focus on infrastructure engineering firms, government agencies, financial houses, and academia. The spyware was downloaded using social engineering techniques.