Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Malware & tools
S0454
malware
Cadelspy
Cadelspy is a backdoor that has been used by APT39.
Platforms
Windows
MITRE ATT&CK ↗
Linked entities · 9
uses
T1010
Application Window Discovery
uses
T1056.001
Keylogging
uses
T1560
Archive Collected Data
uses
T1115
Clipboard Data
uses
T1123
Audio Capture
uses
T1082
System Information Discovery
uses
T1113
Screen Capture
uses
T1120
Peripheral Device Discovery
uses by
G0087
APT39