Candiru (spyware Company)
   HOME

TheInfoList



OR:

Candiru is a private
Tel Aviv Tel Aviv-Yafo ( or , ; ), sometimes rendered as Tel Aviv-Jaffa, and usually referred to as just Tel Aviv, is the most populous city in the Gush Dan metropolitan area of Israel. Located on the Israeli Mediterranean coastline and with a popula ...
-based company founded in 2014 which provides
spyware Spyware (a portmanteau for spying software) is any malware that aims to gather information about a person or organization and send it to another entity in a way that harms the user by violating their privacy, endangering their device's securit ...
and
cyber-espionage Cyber espionage, cyber spying, or cyber-collection is the act or practice of obtaining secrets and information without the permission and knowledge of the holder of the information using methods on the Internet, networks or individual computers th ...
services to government clients. Its management and investors overlap significantly with that of
NSO Group NSO Group Technologies (NSO standing for Niv, Shalev and Omri, the names of the company's founders) is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click surveillance ...
. Its operations began being uncovered in 2019 by researchers at
Citizen Lab The Citizen Lab is an interdisciplinary laboratory based at the Munk School of Global Affairs at the University of Toronto, Canada. It was founded by Ronald Deibert in 2001. The laboratory studies information controls that impact the openness an ...
, Kaspersky, ESET (among others).
Microsoft Microsoft Corporation is an American multinational corporation and technology company, technology conglomerate headquartered in Redmond, Washington. Founded in 1975, the company became influential in the History of personal computers#The ear ...
refers to the company's cyber-espionage operations as "Caramel Tsunami/SOURGUM" while Kaspersky refers to it as "SandCat" Their products exploit zero-days vulnerabilities in a variety of
operating system An operating system (OS) is system software that manages computer hardware and software resources, and provides common daemon (computing), services for computer programs. Time-sharing operating systems scheduler (computing), schedule tasks for ...
s and
web browser A web browser, often shortened to browser, is an application for accessing websites. When a user requests a web page from a particular website, the browser retrieves its files from a web server and then displays the page on the user's scr ...
s to deploy persistent
spyware Spyware (a portmanteau for spying software) is any malware that aims to gather information about a person or organization and send it to another entity in a way that harms the user by violating their privacy, endangering their device's securit ...
implant (dubbed "DevilsTongue" by Microsoft) to remotely control the victim's device. Their products are also reportedly capable of compromising Mac, Android, and iPhone devices. Victims are often social engineered into visiting malicious websites which install spyware via a chain of exploits. Their business model is similar to a
managed service provider Managed services is the practice of outsourcing the responsibility for maintaining, and anticipating need for, a range of processes and functions, ostensibly for the purpose of improved operations and reduced budgetary expenditures through the ...
for cyber-espionage, providing exploits, tools and infrastructure for government clients. It has minimal public presence, requiring employees to sign
non-disclosure agreement A non-disclosure agreement (NDA), also known as a confidentiality agreement (CA), confidential disclosure agreement (CDA), proprietary information agreement (PIA), or secrecy agreement (SA), is a legal contract or part of a contract between at le ...
s and follow strict
operational security Operations security (OPSEC) is a process that identifies critical information to determine whether friendly actions can be observed by enemy intelligence, determines if information obtained by adversaries could be interpreted to be useful to th ...
practices to conceal their source of employment. Its corporate name has changed multiple times from 2014 to 2020. As does many Israeli technology companies it recruits heavily from
Unit 8200 Unit 8200 (, ''Yehida shmone matayim'' "Unit eight two-hundred") is an Israeli Intelligence Corps unit of the Israel Defense Forces responsible for clandestine operation, collecting signal intelligence (SIGINT) and code decryption, counteri ...
, which handles
signals intelligence Signals intelligence (SIGINT) is the act and field of intelligence-gathering by interception of ''signals'', whether communications between people (communications intelligence—abbreviated to COMINT) or from electronic signals not directly u ...
and
cyberwarfare Cyberwarfare is the use of cyberattack, cyber attacks against an enemy State (polity), state, causing comparable harm to actual warfare and/or disrupting vital computer systems. Some intended outcomes could be espionage, sabotage, propaganda, ...
for the Israeli military. Its name and logo references the parasitic fish candiru which has the (likely apocryphal) ability to implant in the human urethra.


Corporate history

Candiru was founded in 2014 by Eran Shorer and Yaakov Weizman. Early NSO Group investor Isaac Zach serves as its
chairman The chair, also chairman, chairwoman, or chairperson, is the presiding officer of an organized group such as a board, committee, or deliberative assembly. The person holding the office, who is typically elected or appointed by members of the gro ...
. Those three have a controlling interest in the company. It reportedly received investment from "Founders Group", an angel investment syndicate operated by NSO Group co-founders Omri Lavie and Shalev Hulio. It is reportedly Israel's second-largest cyber-espionage firm after NSO Group. The company has frequently relocated its offices and changed its corporate registration from 2014 to 2020, most recently to "Saito Tech Ltd". Public court filings pertaining to a lawsuit by a former senior employee indicated that Candiru grew from 12 employees in 2015 to 70 in 2018. By 2016, it had begun closing deals with clients from Europe, the Middle East, Asia, and Latin America. It grossed $10 million in 2016 and $20-$30 million by 2018 with $367 million worth of pending deals with 60 governments. It purportedly uses in-country
intermediaries An intermediary, also known as a middleman or go-between, is defined differently by context. In law or diplomacy, an intermediary is a third party who offers intermediation services between two parties. In trade or barter, an intermediary acts ...
during negotiations. In 2017, Candiru purportedly began development of mobile device spyware. Candiru asked the court to seal documents and hold closed hearings, claiming
national security National security, or national defence (national defense in American English), is the security and Defence (military), defence of a sovereign state, including its Citizenship, citizens, economy, and institutions, which is regarded as a duty of ...
as justification. In 2019, Candiru was valued at $90 million based on the sale of a 10% stake from venture capitalist Eli Wartman to Israel's Universal Motors. The Qatari sovereign wealth fund has reportedly invested in Candiru. In 2020 Candiru incorporated a subsidiary named "Sokoto". As of 2020, its
board Board or Boards may refer to: Flat surface * Lumber, or other rigid material, milled or sawn flat ** Plank (wood) ** Cutting board ** Sounding board, of a musical instrument * Cardboard (paper product) * Paperboard * Fiberboard ** Hardboard, a ...
comprised founding team Eran Shorer, Yaakov Weitzman, chairman/investor Isaac Zach, and a representative of Universal Motors Israel. Its 2021 filings listed minority shareholders Universal Motors Israel, ESOP Management and Trust Services (manager of corporate stock programs), and Optas Industry Ltd (a proxy for the Qatari sovereign wealth fund).


Operational history

Vice A vice is a practice, behaviour, Habit (psychology), habit or item generally considered morally wrong in the associated society. In more minor usage, vice can refer to a fault, a negative character trait, a defect, an infirmity, or a bad or unhe ...
reported in 2019 that
Kaspersky Lab Kaspersky Lab (; ) is a Russian multinational cybersecurity and anti-virus provider headquartered in Moscow, Russia, and operated by a holding company in the United Kingdom. It was founded in 1997 by Eugene Kaspersky, Natalya Kaspersky a ...
had identified Candiru spyware in use by the Uzbekistan State Security Service. The intelligence agency reportedly used Kaspersky antivirus software to test whether the spyware would be detected and configured an official domain ("itt.uz") for the spyware's network communications. This discovery allowed Kaspersky to identify other intelligence agencies using Candiru spyware such as
Saudi Arabia Saudi Arabia, officially the Kingdom of Saudi Arabia (KSA), is a country in West Asia. Located in the centre of the Middle East, it covers the bulk of the Arabian Peninsula and has a land area of about , making it the List of Asian countries ...
and
United Arab Emirates The United Arab Emirates (UAE), or simply the Emirates, is a country in West Asia, in the Middle East, at the eastern end of the Arabian Peninsula. It is a Federal monarchy, federal elective monarchy made up of Emirates of the United Arab E ...
. In April 2021 ESET identified an espionage campaign, possibly perpetrated by Saudi Arabian intelligence, which leveraged Candiru spyware to compromise news outlet
Middle East Eye ''Middle East Eye'' (MEE) is a United Kingdom-based media website and channel that primarily focuses on news related to the Middle East, North Africa, and the broader Muslim world. The ownership of the organisation is undisclosed. Some sources ...
via a watering hole attack. Other targets of this campaign included an Iranian embassy, Italian aerospace companies, and the
Syria Syria, officially the Syrian Arab Republic, is a country in West Asia located in the Eastern Mediterranean and the Levant. It borders the Mediterranean Sea to the west, Turkey to Syria–Turkey border, the north, Iraq to Iraq–Syria border, t ...
n and
Yemen Yemen, officially the Republic of Yemen, is a country in West Asia. Located in South Arabia, southern Arabia, it borders Saudi Arabia to Saudi Arabia–Yemen border, the north, Oman to Oman–Yemen border, the northeast, the south-eastern part ...
i government. In July 2021, Citizen Lab and Microsoft reported widespread usage of Candiru spyware by various government clients to compromise at least 100 worldwide victims across civil society, including politicians, human rights activists, journalists, academics, embassy workers, and dissidents. Spyware control infrastructure was identified in Saudi Arabia, Israel, U.A.E.,
Hungary Hungary is a landlocked country in Central Europe. Spanning much of the Pannonian Basin, Carpathian Basin, it is bordered by Slovakia to the north, Ukraine to the northeast, Romania to the east and southeast, Serbia to the south, Croatia and ...
, and
Indonesia Indonesia, officially the Republic of Indonesia, is a country in Southeast Asia and Oceania, between the Indian Ocean, Indian and Pacific Ocean, Pacific oceans. Comprising over List of islands of Indonesia, 17,000 islands, including Sumatra, ...
. Highly targeted social engineering tricked victims into visiting malicious websites under the
pretext A pretext (: ''pretextual'') is an excuse to do something or say something that is not accurate. Pretexts may be based on a half-truth or developed in the context of a misleading fabrication. Pretexts have been used to conceal the true purpose or r ...
of relevant content. Microsoft's threat intelligence center identified and patched a Windows vulnerability exploited by Candiru spyware in July 2021. Microsoft's analysis of the spyware revealed that in addition to enabling exfiltration of files, messages, and passwords, the spyware also enables the operator to send messages from logged in email and social media accounts directly from the target's computer. Additionally, Citizen Lab reported that Candiru exploited two vulnerabilities in the browser
Google Chrome Google Chrome is a web browser developed by Google. It was first released in 2008 for Microsoft Windows, built with free software components from Apple WebKit and Mozilla Firefox. Versions were later released for Linux, macOS, iOS, iPadOS, an ...
. Google also linked a Microsoft Office exploit to Candiru. In November 2021, the United States Commerce Department added both Candiru and
NSO Group NSO Group Technologies (NSO standing for Niv, Shalev and Omri, the names of the company's founders) is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click surveillance ...
to its sanctioned entities list for supplying spyware to hostile foreign governments. In April 2022, Citizen Lab reported that members of the Catalan independence movement were infected with Candiru spyware as part of a
Spanish government The government of Spain () is the central government which leads the executive branch and the General State Administration of the Kingdom of Spain. The Government consists of the Prime Minister and the Ministers; the prime minister has the o ...
sanctioned domestic surveillance operation against elected officials and activists. NSO Group's
Pegasus Pegasus (; ) is a winged horse in Greek mythology, usually depicted as a white stallion. He was sired by Poseidon, in his role as horse-god, and foaled by the Gorgon Medusa. Pegasus was the brother of Chrysaor, both born from Medusa's blood w ...
spyware was also heavily used in this operation. Investigations by
Amnesty International Amnesty International (also referred to as Amnesty or AI) is an international non-governmental organization focused on human rights, with its headquarters in the United Kingdom. The organization says that it has more than ten million members a ...
and public protest led to CatalanGate and official acknowledgement by the Spanish government. Victims were sent emails leveraging social engineering to convince them to visit a malicious URL, which covertly installed spyware via browser and operating system exploits. These emails leveraged credible pretexts such as official health advisories during the COVID epidemic.


Products and services

Candiru purportedly sells exclusively to government law enforcement agencies and intelligence agencies. It appears to act as " middleman" or "
managed service provider Managed services is the practice of outsourcing the responsibility for maintaining, and anticipating need for, a range of processes and functions, ostensibly for the purpose of improved operations and reduced budgetary expenditures through the ...
", providing delivery mechanisms, remote control infrastructure, spyware tools and software exploits. Clients seems to be responsible for targeting, logistics and the operational security. Candiru has reportedly provided exploits for many zero-day vulnerabilities to clients, which have been patched by the relevant software companies after they are discovered. In at least one case, poor operational security by a client (Ubeki intelligence) resulted in multiple zero-days and network infrastructure being "burned". The company claims that clients are not allowed within the United States, Israel, Russia, China, and Iran. Researchers, including Citizen Lab and Microsoft have identified Candiru spyware victims in Israel and Iran, and potential victims in Russia. Leaked documents and contracts show that Candiru offers a range of exploit delivery methods, including drive-by exploits, tampering with network data, malicious documents, and physical intrusion. It appears to be able to develop new tools as needed and has access to exploits for zero-day vulnerabilities. After compromising the device, a persistent spyware implant (dubbed "DevilsTongue" by Microsoft) is installed to remotely control the victim's device. Social media data, browser cookies and messages from SMS, Viber, WhatsApp, and Signal can be captured. The device's camera/microphone can be captured as well. Services are priced in the tens of millions of dollars based on number of targeted devices and affected countries. Upsold services include access to additional victim data and full remote control of the device. A multi-million dollar add-on called "Sherlock" (likely a cross-operating-system zero-day web browser exploit) purports to provide access on Windows, Android and iOS devices.


References

{{Reflist Spyware companies Companies based in Tel Aviv Computer surveillance