Skip to main content
Mallory
MalwareUsed by 1 actorExploits 2 CVEs

Candiru

Candiru is mercenary spyware referenced in reporting on government digital surveillance and politically motivated targeting of journalists, civil society, and political figures. The content states that from 2024 to 2026, Insikt Group found evidence that at least 16 countries deployed Predator or Candiru spyware against journalists and civil society members, including Angola, Armenia, Azerbaijan, Botswana, the Democratic Republic of the Congo, Egypt, Hungary, Indonesia, Iraq, Kazakhstan, Mongolia, Mozambique, Oman, the Philippines, Saudi Arabia, and Trinidad and Tobago. In August 2025, Insikt Group identified new infrastructure associated with Candiru, including components likely used to deploy DevilsTongue spyware, with active clusters linked to Hungary and Saudi Arabia. Citizen Lab’s CatalanGate reporting documented targeting of Catalan politicians, lawyers, civil society members, and associates with mercenary spyware, including four individuals targeted or infected with Candiru and at least one confirmed infection; at least two individuals were affected by both Pegasus and Candiru. Citizen Lab identified Joan Matamala as the previously unnamed patient zero from its 2021 Hooking Candiru research and confirmed a live persistent Candiru infection on his device. With Matamala’s consent, Citizen Lab shared forensic traces with Microsoft, which identified more than 100 Candiru victims across ten countries. Microsoft found Candiru used Windows zero-days CVE-2021-31979 and CVE-2021-33771, patched in July 2021. Additional Catalan targets identified by Citizen Lab included Elies Campo, Xavier Vives, and Pau Escrich, who were targeted by email. Candiru phishing emails used the domain stat[.]email and impersonated the Government of Spain, the World Health Organization, Barcelona’s Mercantile Registry, and Mobile World Congress; Citizen Lab linked stat[.]email to customized Candiru customer infrastructure. The content also describes a 2024 attempted targeting of German MEP Daniel Freund with Candiru spyware via an email posing as a Ukrainian student; Freund reported he did not click the link and his phone was not infected. High-confidence indicators and artifacts mentioned in the content include the domain stat[.]email, the malware name DevilsTongue in connection with Candiru infrastructure, and exploitation of CVE-2021-31979 and CVE-2021-33771.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2021-31979Windows Kernel Elevation of Privilege VulnerabilityExploited in the wild

Microsoft also discovered two zero-day vulnerabilities (CVE-2021-31979, CVE-2021-33771) employed by Candiru to infect Windows systems, and patched them in July 2021. | Finding: Catalans Targeted with Candiru. In July 2021, we published “Hooking Candiru,” in which we identified and analysed Candiru’s mercenary spyware, in cooperation with Microsoft.

via citizenlabcitizenlab.ca
CVE-2021-33771Windows Kernel Elevation of Privilege VulnerabilityExploited in the wild

Microsoft also discovered two zero-day vulnerabilities (CVE-2021-31979, CVE-2021-33771) employed by Candiru to infect Windows systems, and patched them in July 2021. | Finding: Catalans Targeted with Candiru. In July 2021, we published “Hooking Candiru,” in which we identified and analysed Candiru’s mercenary spyware, in cooperation with Microsoft.

via citizenlabcitizenlab.ca
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
SOURGUM

Finding: Catalans Targeted with Candiru. In July 2021, we published “Hooking Candiru,” in which we identified and analysed Candiru’s mercenary spyware, in cooperation with Microsoft.

via citizenlabcitizenlab.ca
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Reconnaissance

2 techniques
T1589Gather Victim Identity InformationEvidence1

a message sent to Jordi Baylina included a portion of his actual official tax identification number, suggesting that the Pegasus operator had access to this information.

T1591Gather Victim Org InformationEvidence1

The message contained factual information about a company that he administered and purported to be a warning that a similarly-named company was registered in Panama.

Resource Development

1 technique
T1584Compromise InfrastructureEvidence1

The text messages pointed to a cluster of domains pointing to infrastructure previously identified through the Citizen Lab’s Internet scanning and fingerprinting as belonging to NSO Group’s Pegasus infection infrastructure.

Initial Access

2 techniques
T1190Exploit Public-Facing ApplicationEvidence1

As commercial spyware relies on zero-day exploits for deployment, Insikt Group previously assessed that, in addition to posing serious human rights concerns, its misuse threatens the broader cyber ecosystem by enabling the proliferation of critical vulnerabilities.

T1566PhishingEvidence1

We identified a total of seven emails containing the Candiru spyware, via links to the domain name stat[.]email. The email messages were well constructed efforts to entice the targets to click on the links.

Stealth

1 technique
T1036MasqueradingEvidence1

Another common mode of targeting was to masquerade as official notifications from Spanish government entities... The messages also used SMS Sender IDs to masquerade as official agency accounts.

Credential Access

1 technique
T1528Steal Application Access TokenEvidence1

Microsoft’s analysis established that Candiru’s spyware... had functionality allowing the operator to directly use a victim’s cloud accounts on their infected device to send or post messages using their accounts.

Collection

1 technique
T1005Data from Local SystemEvidence1

Our analysis of Candiru’s spyware showed that Candiru was designed for extensive access to the victim device, such as extracting files and browser content...

INDICATORS OF COMPROMISE

IOCs tracked for this family

38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
31 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
7 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app4 years ago
domain●●●●●●●●●●●●View more in app4 years ago
email●●●●●●●●●●●●View more in app4 years ago
domain●●●●●●●●●●●●View more in app4 years ago
domain●●●●●●●●●●●●View more in app4 years ago
ip.v4●●●●●●●●●●●●View more in app4 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching38

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.