← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Tracking Candirus DevilsTongue Spyware in Multiple Countries.
Insikt Group reported discovery of new infrastructure associated with eight Candiru-linked clusters, specifically infrastructure used to deploy and control the DevilsTongue spyware as well as higher-tier operator infrastructure. The finding indicates active expansion or maintenance of a multi-cluster operational footprint that separates initial delivery/deployment mechanisms from command-and-control and operator management layers.
Indicators of Compromise (1 / 115 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | e33cfc9e285729c09e77df9e426587ab | MD5 of 255869de85e2a171993fc5eb8a556d873a1b8966e040f6f55926f2fa2d595cc8 | 2025-08-19 |