Candiru is an Israeli private-sector offensive actor and mercenary spyware vendor founded in 2014 in Tel Aviv and also known as Saito Tech Ltd. It has also operated under corporate names including DF Associates Ltd. and Grindavik Solutions Ltd. Microsoft tracks related activity as SOURGUM and has also mapped it under the private-sector offensive actor family name Caramel Tsunami. Candiru develops and sells surveillance capabilities to government customers and has been sanctioned by the United States through Entity List designation. Candiru is best known for DevilsTongue, a sophisticated modular spyware platform for Windows with user-mode and kernel-mode components. Public reporting has documented stealthy persistence through COM hijacking, in-memory decryption and execution, use of signed drivers, and post-compromise capabilities including credential theft, session theft through browser cookies, file exfiltration, access to messages including Signal content, and abuse of authenticated webmail and social-media sessions to send messages from victim accounts. Candiru-linked operations have also been associated with exploit delivery infrastructure and repeated use of zero-days, including Windows privilege-escalation vulnerabilities CVE-2021-31979 and CVE-2021-33771, Chrome zero-days CVE-2021-21166 and CVE-2021-30551, the Microsoft Office-related exploit CVE-2021-33742, and later reporting around Chrome/WebRTC exploitation including CVE-2022-2294. Operationally, Candiru has used extensive victim-facing infrastructure designed to impersonate media outlets, advocacy organizations, international institutions, and major technology brands. Reporting has linked its ecosystem to the CHAINSHOT exploit kit and identified multiple operational clusters, including infrastructure assessed as tied to customers in Hungary, Saudi Arabia, Indonesia, and Azerbaijan. Some clusters appear to manage victim-facing infrastructure directly, while others use intermediary layers or Tor-based separation. Candiru spyware has been used against civil society and politically sensitive targets, including journalists, dissidents, activists, politicians, academics, embassy personnel, and human rights defenders. Documented victim geographies include Palestine, Israel, Iran, Lebanon, Yemen, Spain, the United Kingdom, Turkey, Armenia, and Singapore. High-profile reporting also tied Candiru activity to surveillance of Catalan political and civil-society figures in Spain, and to targeting connected to Middle Eastern strategic web compromises and watering-hole operations. Those watering-hole campaigns selectively profiled visitors and likely attempted browser exploitation against chosen targets, especially in the Middle East. Candiru is a commercial spyware supplier rather than a nation-state operator, but its tools are used for government surveillance and espionage purposes. Its dominant role is the provision of offensive cyber capability to state customers, with activity centered on covert access, surveillance, credential and data theft, and stealthy post-exploitation against selected individuals and organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Google’s Threat Analysis Group (TAG) published a report that mentions two Chrome zero-day exploits that TAG observed used against targets (CVE-2021-21166 and CVE-2021-30551). The report mentions nine websites that Google determined were used to distribute the exploits. Eight of these websites pointed to IP addresses that matched our CF3 Candiru fingerprint. We thus believe that the attacks that Google observed involving these Chrome exploits were linked to Candiru.
Google’s Threat Analysis Group (TAG) published a report that mentions two Chrome zero-day exploits that TAG observed used against targets (CVE-2021-21166 and CVE-2021-30551). The report mentions nine websites that Google determined were used to distribute the exploits. Eight of these websites pointed to IP addresses that matched our CF3 Candiru fingerprint. We thus believe that the attacks that Google observed involving these Chrome exploits were linked to Candiru.
These threat actors have also weaponised Windows 0day vulnerabilities, tracked as CVE-2021-31979 and CVE-2021-33771, to support delivery. Successful exploitation led to privilege escalation, giving an attacker the ability to escape browser sandboxes and gain kernel code execution.
Google also linked a further Microsoft Office exploit they observed (CVE-2021-33742) to the same operator.
These threat actors have also weaponised Windows 0day vulnerabilities, tracked as CVE-2021-31979 and CVE-2021-33771, to support delivery. Successful exploitation led to privilege escalation, giving an attacker the ability to escape browser sandboxes and gain kernel code execution.
1 more CVE tied to this actor tracked in Mallory.
109 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mercenary spyware operator/vendor selling government-grade surveillance tooling used to infect Windows, iPhones, Android devices, Macs, PCs, and cloud accounts; observed targeting civil society, journalists, dissidents, activists, politicians, and other politically exposed individuals via spyware infrastructure and exploit chains.
Referenced as an Israeli spyware vendor observed among customers of the malicious hosting provider discussed.
Referenced as an Israeli spyware vendor observed among customers of the malicious hosting provider discussed.
Candiru is an Israeli spyware vendor operating multiple infrastructure clusters for managing and delivering its DevilsTongue spyware, with active operations linked to several countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.