{
	"id": "20d29573-f7e2-4af9-85f7-c7ec37145529",
	"created_at": "2026-04-06T00:15:47.989416Z",
	"updated_at": "2026-04-10T03:29:17.219276Z",
	"deleted_at": null,
	"sha1_hash": "f35b67911f352c6fc39b0f87a94a5f1c432bc7a9",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 54778,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 21:42:43 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool Cadelspy\n Tool: Cadelspy\nNames\nCadelspy\nCadelle\nWinSpy\nCategory Malware\nType Reconnaissance, Backdoor, Keylogger, Info stealer\nDescription\n(SecurityWeek) Cadelspy, which is delivered via a dropper, is designed to harvest\nsystem information and clipboard data, log keystrokes, collect the titles of open\nwindows, record audio, capture screenshots and photos via the webcam, and steal\ndocuments printed by the user.\nInformation MITRE ATT\u0026CK Malpedia Last change to this tool card: 30 December 2022\nDownload this tool card in JSON format\nAll groups using tool Cadelspy\nChanged Name Country Observed\nAPT groups\n Cadelle 2011\n1 group listed (1 APT, 0 other, 0 unknown)\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=89ceabfc-a102-4ca1-97b4-937e61678a46\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=89ceabfc-a102-4ca1-97b4-937e61678a46\nPage 1 of 1",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=89ceabfc-a102-4ca1-97b4-937e61678a46"
	],
	"report_names": [
		"listgroups.cgi?u=89ceabfc-a102-4ca1-97b4-937e61678a46"
	],
	"threat_actors": [
		{
			"id": "5d57e839-da14-44ab-b0dc-3a090f45ac4c",
			"created_at": "2022-10-25T16:07:23.42967Z",
			"updated_at": "2026-04-10T02:00:04.595465Z",
			"deleted_at": null,
			"main_name": "Cadelle",
			"aliases": [],
			"source_name": "ETDA:Cadelle",
			"tools": [
				"Antak",
				"Cadelle",
				"Cadelspy",
				"WinSpy"
			],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "1ba5f718-ad64-492c-8a95-e21a46516d22",
			"created_at": "2023-01-06T13:46:38.524357Z",
			"updated_at": "2026-04-10T02:00:03.011902Z",
			"deleted_at": null,
			"main_name": "Cadelle",
			"aliases": [],
			"source_name": "MISPGALAXY:Cadelle",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		}
	],
	"ts_created_at": 1775434547,
	"ts_updated_at": 1775791757,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/f35b67911f352c6fc39b0f87a94a5f1c432bc7a9.pdf",
		"text": "https://archive.orkl.eu/f35b67911f352c6fc39b0f87a94a5f1c432bc7a9.txt",
		"img": "https://archive.orkl.eu/f35b67911f352c6fc39b0f87a94a5f1c432bc7a9.jpg"
	}
}