Caramel Tsunami

Aliases: SOURGUM, Candiru, DEV-0236

Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:12:41

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Caramel Tsunami is a threat actor that specializes in spyware attacks. They have recently resurfaced with an updated toolset and zero-day exploits, targeting specific victims through watering hole attacks. Candiru has been observed exploiting vulnerabilities in popular browsers like Google Chrome and using third-party signed drivers to gain access to the Windows kernel. They have also been linked to other spyware vendors and have been associated with extensive abuses of their surveillance tools.

Reports & references

  • decoded.avast.io — Avast Q2 2022 Threat Report (report)
  • decoded.avast.io — The Return Of Candiru Zero Days In The Middle East (report)
  • citizenlab.ca — Catalangate Extensive Mercenary Spyware Operation Against Catalans Using Pegasus Candiru (report)
  • citizenlab.ca — Pegasus Vs Predator Dissidents Doubly Infected Iphone Reveals Cytrox Mercenary Spyware (report)
  • ESET — Strategic Web Compromises Middle East Pinch Candiru (report)
  • Microsoft — Protecting Customers From A Private Sector Offensive Actor Using 0 Day Exploits And Devilstongue Malware (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references