Candiru
| Candiru | |
|---|---|
| Trade name | {{{trade_name}}} |
| Logo | {{{logo}}} |
| Type | Private |
| Founded | 2014 |
| Founder(s) | Eran Shorer, Yaakov Weizman |
| Defunct | {{{defunct}}} |
| Headquarters | Tel Aviv |
| Industry | Spyware |
| Services | {{{services}}} |
| Parent | {{{parent}}} |
| Subsidiaries | |
| Revenue | {{{revenue}}} |
| Number of employees | {{{num_employees}}} |
| Homepage | {{{homepage}}} |
Candiru (registered as Saito Tech Ltd) is an Israeli spyware company, founded in Tel Aviv in 2014 by Eran Shorer and Yaakov Weizman. Within two months Isaac Zack, an early investor in NSO Group, was the largest shareholder and on the board. It is described as the second Israeli cyber-espionage firm after NSO. It has moved offices and changed its registered name more than once. Saito Tech is the latest. The product Citizen Lab recovered is a Windows implant, DevilsTongue. In November 2021 the US Commerce Department blacklisted Candiru and NSO together.[1][2]
The product
The firm sells exploits and a spyware payload. Sherlock is the exploit framework. DevilsTongue is the implant. Citizen Lab recovered a copy from a politically active victim in western Europe and analysed it with Microsoft. Microsoft patched two privilege-escalation flaws, CVE-2021-31979 and CVE-2021-33771, on 13 July 2021. Citizen Lab also reported two Chrome flaws. Google linked a Microsoft Office exploit to the same firm. The pitch to clients, in a document Citizen Lab published, limits use to “agreed upon territories” and bars the United States, Russia, China, Israel and Iran. NSO has used the same list. Recruitment is reported from Unit 8200. A sale sits under the Israeli defence-export regime, as with NSO and Paragon Solutions.[1]
The victims
Microsoft said it had seen at least 100 victims, in Palestine, Israel, Iran, Lebanon, Yemen, Spain, the United Kingdom, Turkey, Armenia and Singapore: human rights defenders, dissidents, journalists, activists and politicians. Citizen Lab put control infrastructure in Saudi Arabia, Israel, the UAE, Hungary and Indonesia. Targets were drawn to a site by a lure written for them. Other reported targets of related activity included an Iranian embassy, Italian aerospace companies, and Syrian and Yemeni government bodies. The method is a browser or a document, not the zero-click of Pegasus. The take, once the implant is in, is the same kind of take.[1]
The blacklist
On 3 November 2021 the Commerce Department added Candiru and NSO Group to the Entity List, for acting “contrary to the national security or foreign policy interests of the United States.” Two other firms, Positive Technologies of Russia and a Singapore consultancy, were listed the same day. The listing restricts US exports to the company, including the sale of vulnerability research. The New York Times called it the strongest step an American administration had taken against the spyware trade, and noted that both Israeli firms operate under the supervision of the Israeli government. NSO said it sold only to law enforcement and intelligence agencies. Candiru did not offer an equivalent public defence in the reports cited here.[2]
The blacklist is not a finding that the ministry reads the product. It is a finding that the export itself was treated, in Washington, as a foreign-policy problem. The licence remains the Israeli lever. Whether the lever includes a copy of the take is not shown by the listing.
See also
- NSO Group
- Paragon Solutions
- Intellexa
- Unit 8200
- Black Cube
- Cyber and tech firms founded by ex Unit 8200 or occupation forces veterans
Notes
- ↑ 1.0 1.1 1.2 Hooking Candiru, Citizen Lab, 15 July 2021.
- ↑ 2.0 2.1 U.S. Blacklists Israeli Firm NSO Group Over Spyware, New York Times, 3 November 2021.