Monday, April 28, 2025
HomeCyber Security News"Candiru" Spyware Maker Exploits Patched Windows 0-Days & Selling Spyware to...

“Candiru” Spyware Maker Exploits Patched Windows 0-Days & Selling Spyware to Attack iPhones, Androids, Macs, PCs

Published on

SIEM as a Service

Follow Us on Google News

Security researchers recently spotted a cyberweapon, which is a Windows spyware that develops and sells by an Isreal based commercial spyware maker “Candiru” to attack Windows users around the globe.

Candiru is also known as Sourgum is a private firm from Isreal that selling “untraceable” spyware exclusively to governments to attack and monitor iPhones, Androids, Macs, PCs, and cloud accounts.

Researchers from Citizenlab & Micorosft analyzed a Windows spyware copy of Candiru’s that was identified from the politically active victim in Western Europe and discovered that the Candiru was exploited two windows Zero-day(patched recently.) ” CVE-2021-31979 and CVE-2021-33771 “

- Advertisement - Google News

Candiru’s Spyware Infection

Their spyware can infect for spying computers, mobile devices, and cloud accounts to generating multi-million dollars revenue by selling it for various government customers located in Europe, the former Soviet Union, the Persian Gulf, Asia, and Latin America.

Candiru developed Spware consist of several features including malicious links, man-in-the-middle attacks, and physical attacks.

Microsoft claimed that the attacks targeting more than 100 victims around the world including politicians, human rights activists, journalists, academics, embassy workers and political dissidents. 

Candiru Spyware (DevilsTongue) Maker Activities

Microsoft researchers have analyzed this copy of the spyware variant and named it as DevilsTongue that was written in C and C++ with sophisticated novel capabilities.

DevilsTongue seems able to use cookies directly from the victim’s computer on websites such as Facebook, Twitter, Gmail, Yahoo, Mail.ru, Odnoklassniki, and Vkontakte to collect information, read the victim’s messages, and retrieve photos. 

Candiru selling its spyware with licenses, based on the customer’s need and a number of infections.

Candiru also has reportedly recruited hackers from the ranks of Unit 8200, the signals intelligence unit of the Israeli Defence Forces.

According to the Citizen Lab report “The €16 million project proposal allows for an unlimited number of spyware infection attempts, but the monitoring of only 10 devices simultaneously. For an additional €1.5M, the customer can purchase the ability to monitor 15 additional devices simultaneously, and to infect devices in a single additional country.”

Based on the Candiru proposal, spyware can exfiltrate private data from a number of apps and accounts including Gmail, Skype, Telegram, and Facebook.

Also as an add-on feature, it has a feature to stealing browsing history and passwords, turn on the target’s webcam and microphone, and take pictures of the screen. Capturing data from additional apps.

According to the Microsoft report “By examining how Sourgum’s customers were delivering DevilsTongue to victim computers, we saw they were doing so through a chain of exploits that impacted popular browsers and our Windows operating system. Earlier this week, we released updates that, when installed, protect Windows customers from two key Sourgum exploits.”

Microsoft also built around the security for its product against 0-day exploits and DevilsTongue malware.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...