Madi

  • First known sample

    2011
  • Discovery

    2012
  • Number of targets

    100-1000
  • Current status

    Inactive since 2013
  • Type

    Backdoor
  • Targeted platforms

    Windows
  • TOP targeted countries

    Iran , Israel , Pakistan , Ukraine
MADI

More about the Madi campaign, its targets, techniques and tools involved

Learn more
  • The way of propagation

    Social engineering
  • Purpose/Functions

    Cyberespionage
  • Special features

    An unusual number of religious and political ‘distraction’ documents and images were dropped when the initial infection occurred.

  • Targets

    Academia/Research , Business individuals , Critical infrastructure engineering firms , Financial institutions , Government entities
  • Artefacts/Attribution

    Some artifacts and the location of the victims suggested Iranian origins. The attackers were no doubt fluent in Persian - strings written in this language are littered throughout the malware and the C&C tools.

  • Description

    A campaign from 2011 to 2013 to infiltrate computer systems throughout the Middle East, with a focus on infrastructure engineering firms, government agencies, financial houses, and academia. The spyware was downloaded using social engineering techniques.

    Additional information