Candiru

Israeli offensive-cyber firm developing DevilsTongue spyware for Windows, mobile, and browsers. Operates under multiple aliases (Saito Tech, Grindavik Solutions, Taveta, DF Associates). Added to the US Entity List Nov 3 2021 alongside NSO Group.
Candiru is an Israeli offensive-cyber company that develops the DevilsTongue spyware platform targeting Windows systems, mobile devices, and web browsers. Registered under multiple corporate names — including Saito Tech, Grindavik Solutions, Taveta, and DF Associates — Candiru is one of two Israeli spyware companies added by the US Department of Commerce to the Entity List on November 3, 2021, alongside NSO Group. Where NSO is the category's most-visible vendor, Candiru is its most secretive: a firm whose corporate architecture, ownership, and customer disclosures are systematically opaque, and whose product line targets Windows and browsers at a technical depth few peers have replicated.
Candiru founding and the Founders Group cohort
Candiru was founded in 2014 in Tel Aviv by figures drawn from the Israeli private-sector offensive-cyber pipeline, with early backing from Founders Group, an Israeli venture investor. Reported founding cohort includes Eran Shorer and Yaakov Weizman, with reported early board and investor overlap with the founding class of the broader Israeli spyware category. Candiru is the reference case for the Israeli offensive-cyber industry's practice of running multiple registered corporate identities in parallel — a defensive corporate architecture designed to fragment attribution and complicate export-license mapping across successive customer transactions.
DevilsTongue product architecture
DevilsTongue — named by Microsoft's Threat Intelligence Center in its July 2021 disclosure — is a suite of exploits and implants targeting Windows systems, iOS, Android, and multiple browsers (Chrome, Edge, Safari). Unlike Pegasus and Graphite, whose primary attack surface is mobile-device interception, DevilsTongue extends into desktop and browser-based compromise. It has been observed exploiting zero-day vulnerabilities in Windows and in Chromium — a capability set that places Candiru in a technical bracket distinct from mobile-only peers, and one that materially expands the target surface available to Candiru's customer base beyond what a mobile-only vendor can offer.
The Microsoft and Citizen Lab joint July 2021 disclosure
On July 15, 2021, Microsoft and the Citizen Lab jointly published detailed technical reports on DevilsTongue. Citizen Lab identified at least 100 civil-society victims across at least 10 countries — including journalists, human-rights activists, political dissidents, and academics — with confirmed clusters in Iran, Lebanon, Yemen, Spain (Catalan-independence activists), the United Kingdom, and the Palestinian territories. Microsoft's simultaneous disclosure included attributed patches for the Windows vulnerabilities Candiru's operators had exploited. The joint disclosure remains the most technically detailed public forensic account of a single commercial-spyware vendor's operational infrastructure at scale — comparable in depth to any single Pegasus-focused Citizen Lab publication.
Entity List designation and the corporate-identity problem
On November 3, 2021, the US Department of Commerce added Candiru to the Entity List simultaneously with NSO Group. The listing named "Candiru" as the primary entity; Candiru's multiple registered aliases — Saito Tech, Grindavik Solutions, Taveta, DF Associates — are the operative complication for downstream compliance, sanctions screening, and civil discovery. Any counterparty performing US-export-control diligence on a transaction touching an Israeli offensive-cyber vendor now runs its screening against each of Candiru's registered identities separately. The Entity List addition materially constrained Candiru's US-supply-chain access and its ability to move funds through US-correspondent-banking rails — the same constraint set that reshaped NSO's post-listing capital-formation profile.
The Israeli export-license question
Candiru operates under an Israeli Ministry of Defense export license issued and renewed by SIBAT / DECA under Israel's 2007 Defense Export Control Law. The extent to which Candiru's Windows and browser exploit sales — as distinct from its mobile products — fall under the same licensing regime as mobile-interception products is one of the category's live regulatory questions. Israel's 2023 policy tightening, which reduced the number of countries eligible to receive Israeli offensive-cyber exports from 102 to 37, has now materially reshaped that question. Candiru's disclosed customer countries under the pre-2023 regime included several jurisdictions that would not survive the post-2023 filter.
Candiru inside the Israeli offensive-cyber cohort
Candiru sits inside the same Israeli offensive-cyber alumni cohort as NSO Group, Paragon, and QuaDream — but has positioned itself deliberately outside the category's public-facing regulatory dialogue. Where NSO has engaged with US courts, published corporate-governance materials, and disclosed customer-vetting policies, Candiru's public record remains almost entirely composed of adversarial disclosures — Microsoft, Citizen Lab, the US Commerce Department. Its structural distinction from the rest of the cohort is not product architecture but corporate opacity. Candiru is the case study for what an Israeli offensive-cyber vendor looks like when the compliance perimeter is drawn deliberately narrow.
The compliance-perimeter case against Paragon
Candiru is the operative counterpoint to Paragon in the offensive-cyber governance debate. Paragon has bet that a democracies-only policy, US corporate domicile, and public-record governance disclosures can rebuild a compliance perimeter that Entity List peers lost. Candiru has run the opposite bet: minimize public disclosure, operate under multiple corporate identities, and function under Israeli MoD export licensing without engaging the US regulatory or civil-litigation infrastructure at all. Which of those two governance structures survives the next US administration's spyware policy — and the post-2023 Israeli export regime under continuing pressure from named Citizen Lab disclosures — is the category's most-watched governance question.
Primary Sources
Microsoft Threat Intelligence Center report on DevilsTongue (July 15, 2021). Citizen Lab, "Hooking Candiru: Another Mercenary Spyware Vendor Comes into Focus" (July 15, 2021). US Commerce Department Federal Register notice adding Candiru to Entity List (November 3, 2021). Israeli corporate registry filings under Saito Tech, Grindavik Solutions, Taveta, and DF Associates. Reporting in Haaretz and Calcalist on Candiru's licensing and customer profile.
Related Olam Coverage
Unit 8200 · NSO Group · Paragon Solutions · QuaDream · Israel's 2007 Defense Export Control Law · BIS Entity List and Israeli offensive-cyber companies · Cyber-export 102-to-37 tightening

