Sourgum, widely identified as Candiru, is an Israel-based private-sector offensive actor and commercial spyware vendor associated with the development and sale of cyberweapons to government customers. The actor has been linked to precision surveillance operations against more than 100 victims worldwide, with targeting focused on politicians, journalists, human rights activists, academics, embassy personnel, and political dissidents. Reported victim concentration included the Palestinian territories, with additional targeting in Israel, Iran, Lebanon, Yemen, Spain, the United Kingdom, Turkey, Armenia, and Singapore. The group is known for the DevilsTongue malware platform, a modular Windows spyware framework with both user-mode and kernel-mode components. DevilsTongue has supported persistence, privilege escalation, credential theft, browser cookie theft, session hijacking, file collection, registry and WMI querying, SQLite database access, and exfiltration of sensitive data, including decrypted Signal conversations. The malware has also been described as capable of abusing stolen web sessions and sending messages from victim accounts on some services. Operationally, Sourgum has used exploit chains affecting browsers and Windows to install spyware on victim systems, including zero-day vulnerabilities that enabled sandbox escape and kernel code execution. Delivery has been associated with highly targeted, single-use links sent through messaging applications, indicating individualized targeting rather than broad opportunistic compromise. The malware and its deployment methods have also incorporated defense-evasion measures such as encrypted components, unique file builds, and use of a legitimate signed driver to facilitate kernel-level activity. Sourgum is part of the broader private-sector offensive ecosystem in which commercial intrusion and surveillance capabilities are supplied to state customers or other well-resourced clients. Its activity is most consistently characterized as cyber-espionage and covert surveillance rather than financially motivated crime or ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
These threat actors have also weaponised Windows 0day vulnerabilities, tracked as CVE-2021-31979 and CVE-2021-33771, to support delivery. Successful exploitation led to privilege escalation, giving an attacker the ability to escape browser sandboxes and gain kernel code execution.
These threat actors have also weaponised Windows 0day vulnerabilities, tracked as CVE-2021-31979 and CVE-2021-33771, to support delivery. Successful exploitation led to privilege escalation, giving an attacker the ability to escape browser sandboxes and gain kernel code execution.
20 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.