logo

Tracking Candiru’s DevilsTongue Spyware in Multiple Countries

ID: e7d177a0-e10e-463a-8369-c5fe63f12267

STIX ID: report--e7d177a0-e10e-463a-8369-c5fe63f12267

Threat Score

88/100

Uploaded: 2026-08-11

Published Date: 2025-08-04

Last Modified Date: 2025-08-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Insikt Group tracked new infrastructure tied to eight Candiru-linked operational clusters, identifying victim-facing and operator-tier systems used to deploy and control DevilsTongue spyware; five clusters are likely active (including Hungary and Saudi Arabia), one was active until Nov 2024 (Indonesia), and two (Azerbaijan) have uncertain status.** The report details DevilsTongue capabilities and persistence mechanisms, initial-access vectors (spearphishing links, weaponized documents, ad-based delivery), shared exploit usage, a suspected post-acquisition company, extensive IoCs (domains, IPs, a SHA256 hash), and recommended defensive measures.