Candiru is mercenary spyware used against mobile and Windows targets and documented in politically motivated surveillance campaigns against journalists, activists, civil society members, politicians, and lawyers. Citizen Lab identified and analyzed Candiru in its 2021 “Hooking Candiru” research with Microsoft, and later linked it to the CatalanGate campaign, where at least 65 people associated with the Catalan separatist movement were infected with Pegasus or Candiru between 2017 and 2020; four individuals were targeted or infected with Candiru, and at least two were affected by both Pegasus and Candiru. In the Catalan cases, Candiru phishing emails used the domain stat[.]email and impersonated the Government of Spain, the World Health Organization, Barcelona’s Mercantile Registry, and Mobile World Congress. Citizen Lab identified Joan Matamala as the previously unnamed patient zero from Hooking Candiru and confirmed a live persistent Candiru infection on his device; with shared forensic traces, Microsoft identified more than 100 Candiru victims across ten countries and found Candiru exploited Windows zero-days CVE-2021-31979 and CVE-2021-33771, patched in July 2021. Recorded Future’s Insikt Group reported new Candiru infrastructure in August 2025, including components likely used to deploy DevilsTongue spyware, with active clusters linked to Hungary and Saudi Arabia. Insikt Group also found evidence from 2024 to 2026 that at least 16 countries deployed Predator or Candiru spyware against journalists and civil society members, including Angola, Armenia, Azerbaijan, Botswana, the Democratic Republic of the Congo, Egypt, Hungary, Indonesia, Iraq, Kazakhstan, Mongolia, Mozambique, Oman, the Philippines, Saudi Arabia, and Trinidad and Tobago. Additional reporting states German MEP Daniel Freund was targeted in May 2024 with a Candiru lure sent by email from someone posing as a Ukrainian student; he reported that he did not click the link and his phone was not infected. Overall, the content associates Candiru with cross-border mercenary surveillance operations, phishing-based delivery, exploitation of Windows zero-days, and targeting of high-profile political and civil society victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft also discovered two zero-day vulnerabilities (CVE-2021-31979, CVE-2021-33771) employed by Candiru to infect Windows systems, and patched them in July 2021. | Finding: Catalans Targeted with Candiru. In July 2021, we published “Hooking Candiru,” in which we identified and analysed Candiru’s mercenary spyware, in cooperation with Microsoft.
Microsoft also discovered two zero-day vulnerabilities (CVE-2021-31979, CVE-2021-33771) employed by Candiru to infect Windows systems, and patched them in July 2021. | Finding: Catalans Targeted with Candiru. In July 2021, we published “Hooking Candiru,” in which we identified and analysed Candiru’s mercenary spyware, in cooperation with Microsoft.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Finding: Catalans Targeted with Candiru. In July 2021, we published “Hooking Candiru,” in which we identified and analysed Candiru’s mercenary spyware, in cooperation with Microsoft.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
As commercial spyware relies on zero-day exploits for deployment, Insikt Group previously assessed that, in addition to posing serious human rights concerns, its misuse threatens the broader cyber ecosystem by enabling the proliferation of critical vulnerabilities.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spyware strain mentioned in connection with infections targeting people associated with the Catalan separatist movement in Spain.
Mercenary spyware referenced as another spyware platform used against European lawmakers.
Commercial spyware deployed by governments against journalists and civil society members.
Commercial spyware vendor/tooling referenced as deployed by governments for surveillance operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.