Tracking Candiru’s DevilsTongue Spyware in Multiple Countries
ID: e7d177a0-e10e-463a-8369-c5fe63f12267
STIX ID: report--e7d177a0-e10e-463a-8369-c5fe63f12267
Threat Score
88/100
Uploaded: 2026-08-11
Published Date: 2025-08-04
Last Modified Date: 2025-08-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Insikt Group tracked new infrastructure tied to eight Candiru-linked operational clusters, identifying victim-facing and operator-tier systems used to deploy and control DevilsTongue spyware; five clusters are likely active (including Hungary and Saudi Arabia), one was active until Nov 2024 (Indonesia), and two (Azerbaijan) have uncertain status.** The report details DevilsTongue capabilities and persistence mechanisms, initial-access vectors (spearphishing links, weaponized documents, ad-based delivery), shared exploit usage, a suspected post-acquisition company, extensive IoCs (domains, IPs, a SHA256 hash), and recommended defensive measures.
