DevilsTongue is a sophisticated modular Windows spyware platform associated with the Israeli commercial surveillance vendor Candiru, which Microsoft tracks as SOURGUM. It has been used in targeted surveillance operations against politicians, journalists, human rights activists, academics, embassy personnel, dissidents, and other high-value individuals across multiple countries. The malware has been described as a multi-threaded implant with both user-mode and kernel-mode components, designed for stealth, persistence, and post-compromise data collection.
DevilsTongue has been deployed through exploit chains involving web browsers and Windows privilege-escalation vulnerabilities, including zero-days that enabled sandbox escape and kernel code execution. Reported delivery methods include single-use malicious links sent through messaging applications and broader strategic web compromise activity consistent with watering-hole operations. Research has also linked Candiru-associated infrastructure to fake shortened-link redirection and selective exploit delivery against intended victims.
Once installed, DevilsTongue establishes persistence through COM hijacking and executes within trusted Windows processes with elevated privileges. It uses encrypted components and configuration data, in-memory decryption and execution, unique per-file characteristics, and other anti-analysis and detection-evasion measures. The platform is capable of collecting files, querying system and application data, executing WMI-based reconnaissance, and accessing SQLite-backed application stores.
Its surveillance functions include theft of credentials from LSASS and web browsers, theft of browser cookies and web-session material, and abuse of stolen sessions to access online accounts. It also includes dedicated capability to decrypt and exfiltrate Signal conversations. Reporting indicates the malware can act on behalf of the victim in some web contexts, increasing its utility for covert surveillance and follow-on operations.
DevilsTongue is best understood as part of the commercial spyware ecosystem rather than conventional cybercrime tooling. Its operational history, victimology, and exploit-assisted deployment align with mercenary spyware use by government customers conducting precision espionage and domestic or cross-border surveillance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These threat actors have also weaponised Windows 0day vulnerabilities, tracked as CVE-2021-31979 and CVE-2021-33771, to support delivery. Successful exploitation led to privilege escalation, giving an attacker the ability to escape browser sandboxes and gain kernel code execution. | Candiru uses a chain of vulnerabilities in web browsers and Windows to install its DevilsTongue modular multi-threaded backdoor.
These threat actors have also weaponised Windows 0day vulnerabilities, tracked as CVE-2021-31979 and CVE-2021-33771, to support delivery. Successful exploitation led to privilege escalation, giving an attacker the ability to escape browser sandboxes and gain kernel code execution. | Candiru uses a chain of vulnerabilities in web browsers and Windows to install its DevilsTongue modular multi-threaded backdoor.
In July 2021, Google published a blogpost providing details on exploits used by Candiru. It includes CVE‑2021-21166 and CVE-2021-30551 for Chrome and CVE-2021-33742 for Internet Explorer. | "...fake shortened URLs redirecting to exploits and the DevilsTongue implant."
"DevilsTongue is a sophisticated, modular Windows malware." | In July 2022, Avast reported that CVE-2022-2294, a high-severity heap buffer overflow vulnerability in WebRTC within Google Chrome, was exploited to execute shellcode in the browser’s renderer process, targeting users in the Middle East.
Google’s Threat Analysis Group (TAG) disclosed in 2021 that two Google Chrome renderer remote code execution zero-day vulnerabilities (CVE-2021-21166 and CVE-2021-30551) had been exploited by Candiru... Google TAG discovered that CVE-2021-21166 also affected WebKit, prompting Apple to patch it as CVE-2021-1844; however, there is no evidence it was used against Safari users. | "DevilsTongue is a sophisticated, modular Windows malware."
Google’s Threat Analysis Group (TAG) disclosed in 2021 that two Google Chrome renderer remote code execution zero-day vulnerabilities (CVE-2021-21166 and CVE-2021-30551) had been exploited by Candiru. | "DevilsTongue is a sophisticated, modular Windows malware."
"DevilsTongue is a sophisticated, modular Windows malware."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Candiru uses a chain of vulnerabilities in web browsers and Windows to install its DevilsTongue modular multi-threaded backdoor.
Candiru uses a chain of vulnerabilities in web browsers and Windows to install its DevilsTongue modular multi-threaded backdoor.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
"...spyware can be deployed through multiple vectors, including... physical access."
By examining how Sourgum’s customers were delivering DevilsTongue to victim computers, we saw they were doing so through a chain of exploits that impacted popular browsers and our Windows operating system.
DevilsTongue has standard malware capabilities, including file collection, registry querying, running WMI commands, and querying SQLite databases.
These threat actors have also weaponised Windows 0day vulnerabilities, tracked as CVE-2021-31979 and CVE-2021-33771, to support delivery. Successful exploitation led to privilege escalation, giving an attacker the ability to escape browser sandboxes and gain kernel code execution.
For files on disk, PDB paths and PE timestamps are scrubbed, strings and configs are encrypted, and each file has a unique hash.
When the malware is installed, a first-stage ‘hijack’ malware DLL is dropped in a subfolder of C:\Windows\system32\IME\ ; the folders and names of the hijack DLLs blend with legitimate names in the \IME\ directories.
"...spyware can be deployed through multiple vectors, including... physical access."
The main functionality resides in DLLs that are encrypted on disk and only decrypted in memory, making detection more difficult.
The driver’s description is “Physical Memory Access Driver,” and it appears to offer a “by-design” kernel read/write capability. This appears to be abused by DevilsTongue to proxy certain API calls via the kernel to hinder detection
It’s capable of stealing victim credentials from both LSASS and from browsers, such as Chrome and Firefox.
"...allowing the malware to steal credentials from LSASS and browsers..."
It can retrieve cookies from a variety of web browsers. These stolen cookies can later be used by the attacker to sign in as the victim to websites to enable further information gathering.
It’s capable of stealing victim credentials from both LSASS and from browsers, such as Chrome and Firefox.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware/tooling attributed in the content to Candiru, described as exploiting zero-day vulnerabilities in Windows and Chrome.
Spyware associated with Candiru and used for surveillance deployments, with active infrastructure clusters identified in multiple countries.
Commercial spyware (attributed here to Candiru) used to enable intrusive monitoring/surveillance, often in domestic security contexts.
Commercial spyware attributed to vendor Candiru; infrastructure used for delivery/management remains active across multiple geographies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.