Candiru
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:25
- Modified
- 20/12/2025 21:25
- Updated at
- 20/12/2025 21:25
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 35 attack patterns (mitre), 4 malware, 10 sectors, 20 countries, 59 indicators, 5 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (35)
-
T1055 usesProcess Injection
-
T1189 usesDrive-by Compromise
-
Exploits usesT1588.005
-
T1553.002 usesCode Signing
-
T1583.001 usesDomains
-
T1203 usesExploitation for Client Execution
-
T1056 usesInput Capture
-
T1560 usesArchive Collected Data
-
T1608.004 usesDrive-by Target
-
T1068 usesExploitation for Privilege Escalation
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1123 usesAudio Capture
-
T1592 usesGather Victim Host Information
-
T1003 usesOS Credential Dumping
-
T1059 usesCommand and Scripting Interpreter
-
T1589 usesGather Victim Identity Information
-
T1027 usesObfuscated Files or Information
-
T1078 usesValid Accounts
-
T1555 usesCredentials from Password Stores
-
T1071.001 usesWeb Protocols
-
T1584.004 usesServer
-
T1014 usesRootkit
-
T1057 usesProcess Discovery
-
T1005 usesData from Local System
-
T1083 usesFile and Directory Discovery
-
T1059.005 usesVisual Basic
-
T1583.004 usesServer
-
T1566 usesPhishing
-
T1113 usesScreen Capture
-
T1071 usesApplication Layer Protocol
-
T1566.001 usesSpearphishing Attachment
-
T1588.001 usesMalware
-
T1190 usesExploit Public-Facing Application
-
T1115 usesClipboard Data
-
T1547 usesBoot or Logon Autostart Execution
Malware (4)
- DevilsTongue
- Candiru
- Karkadann
- CHAINSHOT
Sectors (10)
- Embassy targets
- Healthcare services targets
- Tech targets
- Defense targets
- Ministries of foreign affairs targets
- Electricity targets
- Finance targets
- Aerospace targets
- Media targets
- Government targets
Countries (20)
- Saudi Arabia targets
- China targets
- Uzbekistan targets
- Palestine targets
- Armenia targets
- Lebanon targets
- Turkey targets
- Singapore targets
- Indonesia targets
- United States of America targets
- Iran, Islamic Republic of targets
- Israel targets
- Yemen targets
- Russian Federation targets
- United Kingdom of Great Britain and Northern Ireland targets
- Spain targets
- Azerbaijan targets
- Hungary targets
- Albania targets
- United Arab Emirates targets
Indicators (59)
-
doubleclick.acindicates -
livesession.bidindicates -
rebrandly.siteindicates -
https://www.smc.gov.ye/wp-includes/js/wp-embed.min.jsindicates -
url-tiny.coindicates -
only-music.netindicates -
bootstrapcdn.netindicates -
bitly.twindicates -
bitly.bzindicates -
bitly.zoneindicates -
bitly.telindicates -
engagebay.ccindicates -
tinyurl.istindicates -
https://rebrandly.site/reconnect-api.phpindicates -
webfx.ccindicates -
https://cuturl.space/1hm39tindicates -
livesesion.bidindicates -
llink.linkindicates -
tinyurl.oneindicates -
webfx.bzindicates -
stylishblock.comindicates -
integrity-labs.ltdindicates -
cuturl.spaceindicates -
bit-ly.siteindicates -
sitei-mprove.netindicates -
bad-shop.netindicates -
querylight.netindicates -
piwiks.comindicates -
fonts-gstatic.netindicates -
site-improve.netindicates -
shortlinkcut.linkindicates -
tinyurl.plusindicates -
visitortrack.netindicates -
medica-tradefair.coindicates -
core-update.comindicates -
bestcarent.orgindicates -
expertglobal.orgindicates -
https://visitortrack.net/sliders.jsindicates -
sherathis.comindicates -
8d486f0c6a0d5089e96f08622047337e387faf63ae858379292a764811e55625indicates -
addthis.eventsindicates -
https://webfex.bz/f/gstatsindicates -
tinyurl.photosindicates -
smartstand.orgindicates -
hotjar.netindicates -
yektenet.comindicates -
static-doubleclick.netindicates -
code-afsanalytics.comindicates -
https://piwiks.com/reconnect.jsindicates -
webfex.bzindicates -
webs-update.comindicates -
https://cuturl.space/lty7uwindicates -
tinyurl.bzindicates -
popsonglist.comindicates -
useproof.ccindicates -
webffx.bzindicates -
https://useproof.cc/1tUAE7A2Jn8WMmq/apiindicates -
instagrarn.coindicates -
datanalytic.orgindicates
Vulnerabilities (CVE) (5)
Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. …
- Published
- 03/11/2021
- Modified
- 21/12/2025
WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows an attacker to perform …
- Published
- 25/08/2022
- Modified
- 20/12/2025
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
- Published
- 03/11/2021
- Modified
- 21/12/2025
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. …
- Attack vector
- NETWORK
- Published
- 02/04/2021
- Modified
- 21/12/2025