Cheshire Cat, also referred to as Flowershop and associated with TeDi signatures SIG17 and SIG18, is a malware platform assessed to have been active from roughly 2002 to 2013 and used against targets across the Middle East. It has been discussed in connection with the broader cluster of state-linked operations surrounding Stuxnet and Duqu, with some reporting suggesting attribution to Israel, but the available information is limited and parts of that attribution remain tentative. The platform is notable primarily for code-overlap relationships rather than extensive public operational detail. Research has identified unique code overlaps between Flowershop/Cheshire Cat and an early Stuxnet-related component called Stuxshop, suggesting a developmental relationship and possible involvement in the wider ecosystem of malware associated with Stuxnet-era operations. This linkage has been cited as evidence of an additional development team participating in early Stuxnet-related work. Publicly available high-confidence detail on Cheshire Cat’s full intrusion lifecycle, victimology, and tradecraft remains sparse. The strongest corroborated characterization is that it was a long-lived malware platform tied to Middle East targeting and technically related to the Stuxnet/Duqu development milieu through shared code. Known aliases include Flowershop and the TeDi-associated designation SIG17/SIG18.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the actor associated with the Flowershop malware platform, which overlaps with the Stuxshop component and appears to represent a fourth team involved in early Stuxnet development.
Presented as the likely identity behind SIG17 and SIG18, a poorly understood espionage cluster with many file and driver IoCs and possible links to Duqu/Stuxnet-era operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.