Candiru: DevilsTongue and the Entity List

Candiru: the Israeli offensive-cyber firm behind DevilsTongue — the Windows, mobile, and browser exploit platform disclosed by Microsoft and Citizen Lab in July 2021 and added to the US Entity List alongside NSO in November 2021.
Candiru is an Israeli offensive-cyber company that develops the DevilsTongue spyware platform targeting Windows systems, mobile devices, and web browsers. Registered under multiple corporate names — including Saito Tech, Grindavik Solutions, Taveta, and DF Associates — Candiru is one of two Israeli spyware companies added by the US Department of Commerce to the Entity List on November 3, 2021, alongside NSO Group. Where NSO is the category's most-visible vendor, Candiru is its most secretive: a firm whose corporate architecture, ownership, and customer disclosures are systematically opaque, and whose product line targets Windows and browsers at a technical depth few peers have replicated.
Candiru founding and the Founders Group cohort
Candiru was founded in 2014 in Tel Aviv by figures drawn from the Israeli private-sector offensive-cyber pipeline, with early backing from Founders Group, an Israeli venture investor. Reported founding cohort includes Eran Shorer and Yaakov Weizman, with reported early board and investor overlap with the founding class of the broader Israeli spyware category. Candiru is the reference case for the Israeli offensive-cyber industry's practice of running multiple registered corporate identities in parallel — a defensive corporate architecture designed to fragment attribution and complicate export-license mapping across successive customer transactions.
DevilsTongue product architecture
DevilsTongue — named by Microsoft's Threat Intelligence Center in its July 2021 disclosure — is a suite of exploits and implants targeting Windows systems, iOS, Android, and multiple browsers (Chrome, Edge, Safari). Unlike Pegasus and Graphite, whose primary attack surface is mobile-device interception, DevilsTongue extends into desktop and browser-based compromise. It has been observed exploiting zero-day vulnerabilities in Windows and in Chromium — a capability set that places Candiru in a technical bracket distinct from mobile-only peers, and one that materially expands the target surface available to Candiru's customer base beyond what a mobile-only vendor can offer.
The Microsoft and Citizen Lab joint July 2021 disclosure
On July 15, 2021, Microsoft and the Citizen Lab jointly published detailed technical reports on DevilsTongue. Citizen Lab identified at least 100 civil-society victims across at least 10 countries — including journalists, human-rights activists, political dissidents, and academics — with confirmed clusters in Iran, Lebanon, Yemen, Spain (Catalan-independence activists), the United Kingdom, and the Palestinian territories. Microsoft's simultaneous disclosure included attributed patches for the Windows vulnerabilities Candiru's operators had exploited. The joint disclosure remains the most technically detailed public forensic account of a single commercial-spyware vendor's operational infrastructure at scale — comparable in depth to any single Pegasus-focused Citizen Lab publication.
The Catalan-independence targeting cluster and the "CatalanGate" record
The Spanish targeting cluster inside the Candiru disclosure record is one of the most operationally documented civil-society targeting cases in the entire commercial-spyware category. Citizen Lab's April 2022 report, published in collaboration with independent security researchers and journalists in Barcelona and Madrid, identified more than 60 Catalan-independence activists, elected officials, academics, and legal-counsel figures whose devices had been targeted by Pegasus, DevilsTongue, or both across the 2017–2020 period. Named individuals included members of the Catalan regional parliament, sitting European Parliament members, and legal counsel to the independence movement.
The Spanish case matters for the category because it moved commercial-spyware accountability from adversarial-jurisdiction targeting (China, Saudi Arabia, UAE) into a democratic-EU-member-state context. The political and legal fallout inside Spain has run through parliamentary inquiry, judicial investigation, and diplomatic exchange with Israel over the Israeli MoD's licensing of Candiru's product to European customers. That fallout is one of the operative reasons the post-2023 Israeli export-license tightening cut the licensed-country list from 102 to 37.
Entity List designation and the corporate-identity problem
On November 3, 2021, the US Department of Commerce added Candiru to the Entity List simultaneously with NSO Group. The listing named "Candiru" as the primary entity; Candiru's multiple registered aliases — Saito Tech, Grindavik Solutions, Taveta, DF Associates — are the operative complication for downstream compliance, sanctions screening, and civil discovery. Any counterparty performing US-export-control diligence on a transaction touching an Israeli offensive-cyber vendor now runs its screening against each of Candiru's registered identities separately. The Entity List addition materially constrained Candiru's US-supply-chain access and its ability to move funds through US-correspondent-banking rails — the same constraint set that reshaped NSO's post-listing capital-formation profile.
The corporate-aliases architecture in operational context
The multiple-registered-identity architecture that Candiru pioneered is now the reference case for how Israeli offensive-cyber vendors manage attribution and licensing risk. The commercial logic is straightforward: an export-control designation attaches to a named legal entity. A vendor operating through parallel legal entities — each holding its own MoD export license, each contracting with its own customers, each maintaining its own banking relationships — creates a compliance perimeter that fragments the attribution burden across counterparties, banks, insurers, and regulators.
The architecture has downstream consequences the category is still working through. Corporate registries, insurance underwriters, and correspondent banks that screen against the Entity List have to maintain and update lists of alias-entities. Civil-litigation discovery against a designated vendor has to trace the operational chain through the alias structure to reach the underlying commercial activity. And the Israeli MoD's own licensing process now has to grapple with whether the post-2023 country-list tightening applies to each alias separately or to the underlying operational entity. Candiru is the operative test case for each of those questions.
The Israeli export-license question
Candiru operates under an Israeli Ministry of Defense export license issued and renewed by SIBAT / DECA under Israel's 2007 Defense Export Control Law. The extent to which Candiru's Windows and browser exploit sales — as distinct from its mobile products — fall under the same licensing regime as mobile-interception products is one of the category's live regulatory questions. Israel's 2023 policy tightening, which reduced the number of countries eligible to receive Israeli offensive-cyber exports from 102 to 37, has now materially reshaped that question. Candiru's disclosed customer countries under the pre-2023 regime included several jurisdictions that would not survive the post-2023 filter.
Candiru inside the Israeli offensive-cyber cohort
Candiru sits inside the same Israeli offensive-cyber alumni cohort as NSO Group and QuaDream — and has positioned itself deliberately outside the category's public-facing regulatory dialogue. Where NSO has engaged with US courts, published corporate-governance materials, and disclosed customer-vetting policies, Candiru's public record remains almost entirely composed of adversarial disclosures — Microsoft, Citizen Lab, the US Commerce Department. Its structural distinction from the rest of the cohort is not product architecture but corporate opacity. Candiru is the case study for what an Israeli offensive-cyber vendor looks like when the compliance perimeter is drawn deliberately narrow.
The compliance-perimeter case
Candiru is the operative counterpoint to Paragon in the offensive-cyber governance debate. Paragon has bet that a democracies-only policy, US corporate domicile, and public-record governance disclosures can rebuild a compliance perimeter that Entity List peers lost. Candiru has run the opposite bet: minimize public disclosure, operate under multiple corporate identities, and function under Israeli MoD export licensing without engaging the US regulatory or civil-litigation infrastructure at all. Which of those two governance structures survives the next US administration's spyware policy — and the post-2023 Israeli export regime under continuing pressure from named Citizen Lab disclosures — is the category's most-watched governance question.
Primary Sources
Microsoft Threat Intelligence Center report on DevilsTongue (July 15, 2021). Citizen Lab, "Hooking Candiru: Another Mercenary Spyware Vendor Comes into Focus" (July 15, 2021). Citizen Lab, "CatalanGate" report (April 2022). US Commerce Department Federal Register notice adding Candiru to Entity List (November 3, 2021). Israeli corporate registry filings under Saito Tech, Grindavik Solutions, Taveta, and DF Associates. Reporting in Haaretz and Calcalist on Candiru's licensing and customer profile.
Related Olam Coverage
The Israeli Offensive-Cyber Cluster
NSO Group · Candiru · QuaDream · Paragon · Unit 8200 · Shalev Hulio
See also: The Builders · Olam AI Citation Share Index — 2026 Series · Israeli Cyber Public Companies Citation Share Index 2026




