Threat actor
Candiru
Last fetched
Candiru is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
Israeli firm Candiru was founded in 2015 by Eran Shorer and Yaakov Weizman. According to Haaretz, the largest shareholder in Isaac Zack, who has been its chairman since the beginning and was also a founding funder of NSO. In 2021, malware manufactured by Candiru was found on the phones of politicians, journalists, and scholars in Iran, Yemen, Israel, the United Kingdom, and Turkey. Candiru has changed names multiple times, to Grindavik, then DF Associates, then Taveta, then Saito Tech, but it is still commonly known as Candiru. Founded in 2014, is thought to be Israel’s second-largest spyware maker after NSO. With funding from NSO investors as well as the government of Qatar, its systems have been found to have been operated by multiple countries, including Saudi Arabia, Israel, UAE, Hungary, Indonesia, and Uzbekistan. In November 2021, the US Commerce Department added Candiru and NSO to its trade blacklist. Researchers from Recorded Future's Insikt Group have identified active infrastructure associated with Candiru's spyware, known as DevilsTongue, in Hungary and Saudi Arabia. This spyware targets Windows systems and is believed to be deployed through spear-phishing emails, malicious links, and compromised websites. In 2025, Integrity Partners, a U.S. investment firm, acquired Candiru’s assets for up to $30 million, moving its operations and staff to the new entity Integrity Labs Ltd., which is not subject to U.S. sanctions. The deal aims to bypass U.S. restrictions after Candiru was blacklisted in 2021 over national security concerns.
Techniques by tactic
No ATT&CK techniques are recorded for Candiru in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Candiru today — this states the absence of a published link, not that Candiru has no infrastructure.
References
- https://7amleh.org/storage/Israel%E2%80%99s%20Surveillance%20Industry%20english4.pdf
- https://www.fastcompany.com/91024985/spyware-companies-helping-governments-hack-their-citizens
- https://www.cima.ned.org/publication/spyware-an-unregulated-and-escalating-threat-to-independent-media/
- https://www.haaretz.com/israel-news/tech-news/2020-09-07/ty-article/.premium/mobile-spytech-millions-in-gulf-deals-top-secret-israeli-cyberattack-firm-reve/0000017f-e1eb-d568-ad7f-f3eb36390000
- https://www.singapore-samizdat.com/p/a-timeline-of-singapore-and-spyware
- https://www.forbes.com/sites/thomasbrewster/2019/10/03/meet-candiru-the-super-stealth-cyber-mercenaries-hacking-apple-and-microsoft-pcs-for-profit/
- https://www.theguardian.com/technology/2021/nov/16/israeli-firm-candiru-spyware-linked-to-attacks-on-websites-uk-middle-east
- https://therecord.media/candiru-spyware-active-infrastructure-hungary-saudi-arabia
- https://www.calcalistech.com/ctechnews/article/r1er11mi61e
- https://assets.recordedfuture.com/content/dam/insikt-report-pdfs/2025/cta-2025-0805.pdf
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Candiru into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.