Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Private Sector Offensive Actors3 malware familiesExploits CVEs in the wild

Candiru

Also known ascandiruCaramel TsunamiDEV-0236

Candiru is an Israeli private sector offensive actor and spyware vendor. Known aliases in the provided content include Caramel Tsunami and DEV-0236; Microsoft also tracks activity linked to Candiru as SOURGUM. The company is described as a mercenary hacking company and commercial legal entity that creates and sells cyberweapons to government customers. It was added to the U.S. Department of Commerce Entity List in November 2021. Candiru is associated with the DevilsTongue spyware, described as a sophisticated modular Windows spyware with user- and kernel-mode components, persistence via COM hijacking, use of a signed driver (physmem.sys), in-memory decryption and execution, and capabilities to steal credentials and access Signal messages. Recorded Future identified victim-facing deployment and command-and-control infrastructure as well as higher-tier operator infrastructure linked to Candiru, and reported eight distinct operational clusters, with five assessed as likely still active, including clusters linked to Hungary and Saudi Arabia. Other reporting in the content links Candiru-associated activity to customers or clusters tied to Indonesia, Azerbaijan, Saudi Arabia, the UAE, Uzbekistan, and Hungary. The content states Candiru spyware has targeted journalists, dissidents, civil society, and political figures. Citizen Lab reported at least 65 individuals were targeted or infected with Pegasus or Candiru in the CatalanGate case, including four targeted or infected with Candiru, and identified Joan Matamala as a confirmed Candiru victim. Microsoft and Citizen Lab reported Candiru spyware had compromised at least 100 victims globally across multiple countries and victim categories. The content also notes reporting that German MEP Daniel Freund was likely targeted by spyware originating from Candiru before EU elections. Candiru-linked exploitation in the provided content includes use of Windows zero-days CVE-2021-31979 and CVE-2021-33771, Chrome zero-days CVE-2021-21166 and CVE-2021-30551, an Internet Explorer zero-day later assigned CVE-2021-33742, and reported exploitation of Chrome/WebRTC CVE-2022-2294. ESET linked watering-hole activity targeting high-profile Middle Eastern websites, especially Yemen-related sites, to operators assessed with medium confidence to be Candiru customers. That activity used compromised websites for visitor profiling and selective redirection toward likely browser exploit chains. The content also references Candiru phishing infrastructure and impersonation themes involving the Government of Spain, the World Health Organization, Barcelona’s Mercantile Registry, and Mobile World Congress. The provided content describes Candiru as founded in 2014 by Eran Shorer and Yaakov Weizmann and operating as Saito Tech Ltd.; it also references DF Associates Ltd. and Grindavik Solutions Ltd. as later corporate names. A 2025 report cited in the content states Candiru was acquired by Integrity Partners and that assets and employees were transferred to a newly established entity, with Integrity Labs Ltd. identified as a suspected related company.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Non-Governmental Organizations
  • Academia & Research
  • Software & Services

Where they target

Geographies tied to known operations.

  • 🇪🇸 Spain
  • 🇺🇸 United States
MITRE ATT&CK

Tradecraft

24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics35 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1591
Gather Victim Org Information
TA0042
Resource Development
3 techniques
T1583
Acquire Infrastructure
T1583.006
Web Services
T1584×2
Compromise Infrastructure
T1588
Obtain Capabilities
T1588.001
Malware
T1588.005
Exploits
TA0001
Initial Access
4 techniques
T1078
Valid Accounts
T1189×3
Drive-by Compromise
T1190×2
Exploit Public-Facing Application
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
TA0002
Execution
1 technique
T1203×3
Exploitation for Client Execution
TA0003
Persistence
2 techniques
T1078
Valid Accounts
T1546
Event Triggered Execution
T1546.015
Component Object Model Hijacking
TA0004
Privilege Escalation
3 techniques
T1068×2
Exploitation for Privilege Escalation
T1078
Valid Accounts
T1546
Event Triggered Execution
T1546.015
Component Object Model Hijacking
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1078
Valid Accounts
T1620
Reflective Code Loading
TA0006
Credential Access
4 techniques
T1003
OS Credential Dumping
T1003.001
LSASS Memory
T1528
Steal Application Access Token
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
T1557
Adversary-in-the-Middle
TA0009
Collection
2 techniques
T1005
Data from Local System
T1557
Adversary-in-the-Middle
TA0011
Command and Control
1 technique
T1071
Application Layer Protocol
WEAPONIZED

Associated vulnerabilities

6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.

CVE-2021-21166Data race in audio in Google ChromeIn the wildEvidence2

Google’s Threat Analysis Group (TAG) disclosed in 2021 that two Google Chrome renderer remote code execution zero-day vulnerabilities (CVE-2021-21166 and CVE-2021-30551) had been exploited by Candiru... Google TAG discovered that CVE-2021-21166 also affected WebKit, prompting Apple to patch it as CVE-2021-1844; however, there is no evidence it was used against Safari users.

CVE-2021-30551Type Confusion in Google Chrome V8In the wildEvidence2

Google’s Threat Analysis Group (TAG) disclosed in 2021 that two Google Chrome renderer remote code execution zero-day vulnerabilities (CVE-2021-21166 and CVE-2021-30551) had been exploited by Candiru.

CVE-2021-33742Windows MSHTML Platform Remote Code Execution VulnerabilityIn the wildEvidence2

Following a fingerprinting phase, targets were served an Internet Explorer zero-day exploit, later assigned CVE-2021-33742 and patched by Microsoft in June 2021.

CVE-2022-2294Heap Buffer Overflow in Google Chrome WebRTCIn the wildEvidence2

In July 2022, Avast reported that CVE-2022-2294, a high-severity heap buffer overflow vulnerability in WebRTC within Google Chrome, was exploited to execute shellcode in the browser’s renderer process, targeting users in the Middle East.

CVE-2021-31979Windows Kernel Elevation of Privilege VulnerabilityIn the wildEvidence1

Microsoft also discovered two zero-day vulnerabilities (CVE-2021-31979, CVE-2021-33771) employed by Candiru to infect Windows systems, and patched them in July 2021.

1 more CVE tied to this actor tracked in Mallory.

IOCS

Observables

47 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

breakglass intelNews
Mar 15, 2026
Competent Malware, Incompetent Infrastructure: A VIPKeylogger Operator Builds a Steganographic Kill Chain, Leaves XAMPP Dashboard Open, and Leaks Their Own SMTP Credentials - Breakglass Intelligence - Breakglass Intelligence

Referenced as an Israeli spyware vendor observed among customers of the malicious hosting provider discussed.

Read more
breakglass intelNews
Mar 15, 2026
Competent Malware, Incompetent Infrastructure: A VIPKeylogger Operator Builds a Steganographic Kill Chain, Leaves XAMPP Dashboard Open, and Leaks Their Own SMTP Credentials - Breakglass Intelligence - Breakglass Intelligence

Referenced as an Israeli spyware vendor observed among customers of the malicious hosting provider discussed.

Read more
the hacker newsNews
Aug 11, 2025
⚡ Weekly Recap: BadCam Attack, WinRAR 0-Day, EDR Killer, NVIDIA Flaws, Ransomware Attacks & More

Candiru is an Israeli spyware vendor operating multiple infrastructure clusters for managing and delivering its DevilsTongue spyware, with active operations linked to several countries.

Read more
recorded future blogNews
Aug 5, 2025
Tracking Candiru’s DevilsTongue Spyware in Multiple Countries

Mercenary spyware vendor and associated operator clusters deploying the DevilsTongue Windows spyware via victim-facing infrastructure and higher-tier operator infrastructure; linked to multiple government customers and campaigns including watering-hole and spearphishing-style single-use link delivery, and exploitation of browser/IE zero-days.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping24

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs6

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables47

Domains, IPs, and hashes tied to this actor, refreshed continuously.