Candiru is an Israeli commercial spyware vendor founded in Tel Aviv in 2014 that supplies surveillance tools exclusively to government customers. It operates as Saito Tech Ltd. and has previously used the corporate names Candiru Ltd., DF Associates Ltd., Grindavik Solutions Ltd., and Taveta Ltd. Microsoft tracks associated activity as Caramel Tsunami, formerly SOURGUM and DEV-0236. Candiru is a private-sector offensive actor rather than an established Israeli state-directed threat group. The United States Department of Commerce added the company to its Entity List in November 2021 for supplying spyware to foreign governments engaged in malicious activities. Candiru's tools support covert surveillance and espionage against politicians, journalists, human rights defenders, activists, dissidents, academics, and embassy personnel. In 2021, at least 100 victims were identified across multiple countries, with approximately half of Microsoft's observed victims in Palestine. Candiru spyware also targeted members of Catalan open-source and digital-voting communities, including an individual residing in the United States. Its principal publicly analyzed implant, DevilsTongue, is modular Windows spyware with user-mode and kernel-mode components. It supports file exfiltration, credential theft from browsers and LSASS, access to Signal desktop messages, and theft and abuse of browser cookies to impersonate victims on email and social platforms. Persistence uses COM hijacking. Encrypted components, in-memory payload execution, metadata removal, and a signed third-party driver supporting kernel-memory access complicate detection and analysis. Documented delivery methods include spearphishing links, weaponized Office documents, and watering-hole attacks. Exploit delivery can fingerprint prospective victims before selectively deploying browser exploits. Candiru-associated activity has exploited Chrome vulnerabilities including CVE-2021-21166, CVE-2021-30551, and CVE-2022-2294, Internet Explorer vulnerability CVE-2021-33742, and Windows privilege-escalation vulnerabilities CVE-2021-31979 and CVE-2021-33771. Its infrastructure has also shown overlap with the CHAINSHOT exploit kit. Associated operators use direct infrastructure administration, intermediary servers, and Tor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Google’s Threat Analysis Group disclosed in 2021 that two Google Chrome renderer remote code execution zero-day vulnerabilities (CVE-2021-21166 and CVE-2021-30551) had been exploited by Candiru.
These exploits were distributed via single-use links sent to specific targets, who were believed to be located in Armenia.
Candiru was found to have exploited two Microsoft Windows zero-days, CVE-2021-31979 and CVE-2021-33771, to grant attackers full privileges on victim machines.
Following a fingerprinting phase, targets were served an Internet Explorer zero-day exploit, later assigned CVE-2021-33742 and patched by Microsoft in June 2021.
Candiru was found to have exploited two Microsoft Windows zero-days, CVE-2021-31979 and CVE-2021-33771, to grant attackers full privileges on victim machines.
2 more CVEs tied to this actor tracked in Mallory.
327 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mercenary spyware operator/vendor selling government-grade surveillance tooling used to infect Windows, iPhones, Android devices, Macs, PCs, and cloud accounts; observed targeting civil society, journalists, dissidents, activists, politicians, and other politically exposed individuals via spyware infrastructure and exploit chains.
Referenced as an Israeli spyware vendor observed among customers of the malicious hosting provider discussed.
Referenced as an Israeli spyware vendor observed among customers of the malicious hosting provider discussed.
Candiru is an Israeli spyware vendor operating multiple infrastructure clusters for managing and delivering its DevilsTongue spyware, with active operations linked to several countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.