DevilsTongue is a modular Windows spyware platform developed by the Israeli commercial surveillance vendor Candiru, whose activity Microsoft tracks as SOURGUM. Written in C and C++, it is multithreaded and incorporates user-mode and kernel-mode components. Candiru supplies surveillance tools to government customers that select targets and conduct operations. DevilsTongue has been used against politicians, journalists, human rights defenders, academics, embassy personnel, and political dissidents. Investigations disclosed in 2021 identified more than 100 victims worldwide, approximately half located in the Palestinian Authority.
DevilsTongue collects files, steals credentials from LSASS and browsers, and decrypts and exfiltrates Signal desktop conversations. It steals browser cookies to impersonate victims on online services and can send messages through compromised accounts. It also supports registry queries, WMI commands, and access to SQLite databases. Persistence relies on COM hijacking. Its evasion mechanisms include encrypted payloads and configuration data, in-memory execution of decrypted components, removal of identifying metadata, and per-file variation that complicates signature-based detection. It abuses a legitimate signed third-party driver for kernel-memory access and API-call proxying.
Infection campaigns use targeted malicious links, weaponized Office documents, and compromised websites in watering-hole attacks. Browser exploitation is combined with Windows privilege escalation to escape browser sandboxes and obtain kernel code execution. Documented exploit chains include the Windows zero-day vulnerabilities CVE-2021-31979 and CVE-2021-33771, patched in July 2021, and Chrome vulnerabilities including CVE-2021-21166, CVE-2021-30551, and CVE-2022-2294. Single-use exploit links and selective targeting help limit exposure of the exploitation infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Following a fingerprinting phase, targets were served an Internet Explorer zero-day exploit, later assigned CVE-2021-33742 and patched by Microsoft in June 2021.
Google’s Threat Analysis Group disclosed in 2021 that two Google Chrome renderer remote code execution zero-day vulnerabilities (CVE-2021-21166 and CVE-2021-30551) had been exploited by Candiru.
Candiru was found to have exploited two Microsoft Windows zero-days, CVE-2021-31979 and CVE-2021-33771, to grant attackers full privileges on victim machines.
In July 2022, Avast reported that CVE-2022-2294, a high-severity heap buffer overflow vulnerability in WebRTC within Google Chrome, was exploited to execute shellcode in the browser’s renderer process, targeting users in the Middle East.
Candiru was found to have exploited two Microsoft Windows zero-days, CVE-2021-31979 and CVE-2021-33771, to grant attackers full privileges on victim machines.
These exploits were distributed via single-use links sent to specific targets, who were believed to be located in Armenia.
CVE-2023-5217 (Google Chrome) — Candiru (DevilsTongue).
"DevilsTongue is a sophisticated, modular Windows malware."
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“DevilsTongue, the name given by Microsoft to the Windows-based spyware developed by Candiru, is a complex, modular, multi-threaded malware written in C and C++ with a wide range of capabilities.”
Candiru uses a chain of vulnerabilities in web browsers and Windows to install its DevilsTongue modular multi-threaded backdoor.
Candiru uses a chain of vulnerabilities in web browsers and Windows to install its DevilsTongue modular multi-threaded backdoor.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
"...spyware can be deployed through multiple vectors, including... physical access."
By examining how Sourgum’s customers were delivering DevilsTongue to victim computers, we saw they were doing so through a chain of exploits that impacted popular browsers and our Windows operating system.
DevilsTongue has standard malware capabilities, including file collection, registry querying, running WMI commands, and querying SQLite databases.
These threat actors have also weaponised Windows 0day vulnerabilities, tracked as CVE-2021-31979 and CVE-2021-33771, to support delivery. Successful exploitation led to privilege escalation, giving an attacker the ability to escape browser sandboxes and gain kernel code execution.
For files on disk, PDB paths and PE timestamps are scrubbed, strings and configs are encrypted, and each file has a unique hash.
When the malware is installed, a first-stage ‘hijack’ malware DLL is dropped in a subfolder of C:\Windows\system32\IME\ ; the folders and names of the hijack DLLs blend with legitimate names in the \IME\ directories.
"...spyware can be deployed through multiple vectors, including... physical access."
The main functionality resides in DLLs that are encrypted on disk and only decrypted in memory, making detection more difficult.
The driver’s description is “Physical Memory Access Driver,” and it appears to offer a “by-design” kernel read/write capability. This appears to be abused by DevilsTongue to proxy certain API calls via the kernel to hinder detection
It’s capable of stealing victim credentials from both LSASS and from browsers, such as Chrome and Firefox.
"...allowing the malware to steal credentials from LSASS and browsers..."
It can retrieve cookies from a variety of web browsers. These stolen cookies can later be used by the attacker to sign in as the victim to websites to enable further information gathering.
It’s capable of stealing victim credentials from both LSASS and from browsers, such as Chrome and Firefox.
247 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware/tooling attributed in the content to Candiru, described as exploiting zero-day vulnerabilities in Windows and Chrome.
Spyware associated with Candiru and used for surveillance deployments, with active infrastructure clusters identified in multiple countries.
Commercial spyware (attributed here to Candiru) used to enable intrusive monitoring/surveillance, often in domestic security contexts.
Commercial spyware attributed to vendor Candiru; infrastructure used for delivery/management remains active across multiple geographies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.