Mahdi is a malware family used for targeted cyber espionage. It was initially discovered in February 2012 and publicly reported in July 2012. Kaspersky Lab and Seculert assessed that it had been active since at least December 2011 and had infected at least 800 computers, primarily in Iran and other Middle Eastern countries, with the highest number of infections reported in Iran. Reported targets included sensitive infrastructure organizations, engineering students, financial services institutions, and government embassies. Mahdi was described as less sophisticated than Stuxnet and built using existing publicly available software components. Its capabilities included stealing files and conducting extensive surveillance, including monitoring emails, text messages and chats, keylogging, audio recording, and screen capture. The malware’s naming derived from operator artifacts found on infected systems, including a folder named Mehdi/Mahdi and a text file named "mahdi.txt".
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyber-espionage malware used in targeted campaigns. Capabilities described include stealing files, monitoring emails and chats/text messages, audio recording, keylogging, screen capture/monitor activity capture, and taking pictures of on-screen activity.
See also ... Mahdi (malware) ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.