Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
ID: 11fb6fcd-bab2-53c6-b38a-0ef0e76e2b2a
STIX ID: report--11fb6fcd-bab2-53c6-b38a-0ef0e76e2b2a
Feed Name: Recorded Future Blog
Executive Summary: Recorded Future Insikt Group identified eight distinct infrastructure clusters linked to Candiru’s DevilsTongue spyware—five likely still active—detailing victim-facing and operator-tier components, cluster-specific administration differences, and a suspected corporate entity tied to a recent asset transfer; the report outlines DevilsTongue’s sophisticated Windows capabilities (user- and kernel-mode components, COM hijacking, in-memory payloads, credential and Signal data theft), documented exploitation vectors (malicious links, weaponized Office documents, watering-hole attacks and browser zero-days), observed geographic targeting and victim types, and recommended mitigations including hunting for indicators, patching, and stricter device separation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
