All Posts
Key Points on Candiru Spyware

Key Points on Candiru Spyware

Candiru, an Israeli spyware firm (now operating as Saito Tech Ltd. and recently acquired by Integrity Partners in 2025), develops advanced surveillance tools like DevilsTongue, primarily targeting Windows systems but with capabilities across iOS, Android, and other platforms. It sells to governments for espionage, though evidence suggests misuse against journalists, activists, and politicians in regions like the Middle East and Europe.

E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram
March 5, 20265 min read
16

Operation: The spyware uses modular components for stealthy data collection, including browser credentials, Signal messages, and real-time surveillance, often exploiting zero-day vulnerabilities for installation without user interaction.

Vulnerabilities and Risks: Relies on flaws like CVE-2022-2294 in Chrome and Windows privilege escalations (e.g., CVE-2021-31979), but patches from vendors like Microsoft and Google have mitigated some threats; ongoing evolution raises concerns about persistent risks.

Infection and Exfiltration: Infections occur via browser exploits or phishing, with data sent encrypted to command servers; this has targeted high-profile individuals, highlighting ethical issues in spyware deployment.

Development: Built through iterative zero-day research and modular coding, with sales models limiting concurrent uses to vetted clients, though blacklisting by the US in 2021 hasn’t fully halted operations.

Recent Developments: As of 2025-2026, active infrastructure persists in countries like Hungary and Saudi Arabia, amid legal probes in Spain and investor warnings about human rights risks.

Technical Mechanisms

DevilsTongue, Candiru’s flagship spyware, functions as a stealthy implant that gains kernel-level access to harvest data like passwords and messages. It evades detection by executing in memory and using legitimate drivers. 34 For protection, users should apply patches promptly and use tools like Microsoft’s Defender.

Ethical and Global Impact

Research suggests Candiru’s tools have been used in politically motivated surveillance, contributing to broader concerns about commercial spyware proliferation. International efforts, including US sanctions, aim to curb this, but enforcement remains uneven.

How Candiru Spyware Works

DevilsTongue operates through layered, encrypted components to maintain stealth. It achieves persistence via COM hijacking, modifying registry keys (e.g., HKLM\SOFTWARE\Classes\CLSID{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32) to load a malicious DLL instead of legitimate ones like wmiutils.dll. This DLL, dropped in C:\Windows\system32\IME\ subfolders, decrypts resources using AES-256-CBC and zlib, loading legitimate DLLs to preserve system functionality while injecting spyware.

A signed third-party driver (physmem.sys) enables kernel access, proxying API calls to evade detection. All payloads execute in-memory, with scrubbed metadata, encrypted strings, and unique hashes per instance. Configuration is stored separately in obfuscated JSON (Base64 UTF-16 encoded URLs for C&C).

Functionality includes stealing browser cookies for impersonation on sites like Facebook, Gmail, and VK, decrypting Signal messages, capturing screenshots, activating webcams/microphones, and running WMI commands. It uses shellcode to manipulate LoadLibraryExW return values, ensuring hijacked processes appear normal. Evasion involves blending files with system directories and proxying calls via kernel to make actions seem from other processes.

Infection Process

Infections are targeted and multi-vector:

Watering Hole Attacks: Compromise sites (e.g., Middle East news agencies) with persistent XSS to inject JavaScript redirecting victims to exploit servers.

Spearphishing: Malicious links or weaponized Office documents (e.g., via CVE-2021-33742) delivered via email or messaging apps like WhatsApp.

Zero-Click Exploits: Browser-based (e.g., CVE-2022-2294 via WebRTC) for shellcode execution, followed by sandbox escape and privilege escalation (e.g., CVE-2021-31979).

Other Vectors: Man-in-the-middle, physical access, or programmatic ads via “Sherlock” for demographic targeting.

Exploit servers fingerprint devices (e.g., 50+ data points like timezone, plugins) before delivering payloads encrypted with RSA-2048/AES-256-CBC. Post-infection, DevilsTongue drops files (e.g., HW.sys for BYOVD kernel exploit) and hijacks COM for persistence.

Data Exfiltration and Transmission

Data is harvested in-memory: credentials from LSASS/browsers, Signal messages decrypted, cookies for account impersonation. Exfiltration uses C&C servers (e.g., msstore.io, adtracker.link) via encrypted channels. Infrastructure includes over 750 domains mimicking advocacy/media sites (e.g., amnestyinternational[.]co, cnninternational[.]news), resolved to IPs like 185.181.8.155. Clusters employ Tor for obfuscation, with victim-facing and operator tiers. No direct DNS/SNI; traffic anonymized via VPS providers like DigitalOcean.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
Share
Weekly Briefing

Get the Weekly Cyberwarfare Briefing

State cyber operations, AI-powered attack campaigns, and offensive cyber industry developments — delivered to your inbox every week.

Defensive intelligence only. No spam — unsubscribe anytime.