Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Carmine Tsunami

Also known as: DEV-0196, QuaDream

Description

Carmine Tsunami is a threat actor linked to an Israel-based private sector offensive actor called QuaDream. QuaDream sells a platform called REIGN to governments for law enforcement purposes, which includes exploits, malware, and infrastructure for data exfiltration from mobile devices. Carmine Tsunami is associated with the iOS malware called KingsPawn and has targeted civil society victims, including journalists, political opposition figures, and NGO workers, in various regions. They utilize domain registrars and inexpensive cloud hosting providers, often using single domains per IP address and deploying free Let's Encrypt SSL certificates.

AI Analysis

· 2 weeks ago

Executive Summary

Carmine Tsunami (DEV-0196, QuaDream) is a threat actor linked to an Israel-based private sector offensive actor known as Qua Dream. They are associated with the iOS malware KingsPawn and have targeted civil society actors in various regions. Their operations include mobile device exploitation, domain registrar abuse, and use of cloud hosting infrastructure.

Goals & Targeting

Carmine Tsunami appears to target civil society actors, including journalists,政治 opposition figures, and NGO workers, likely with the intent of conducting surveillance or intelligence gathering. Their focus on these sectors suggests a potential interest in monitoring dissidents or activists. The actor's targeting extends across multiple regions, indicating either widespread geographic interests or specific operational objectives.

Enhanced Description

Carmine Tsunami is a cyber threat actor tied to QuaDream, an Israeli private sector entity that develops surveillance tools like the REIGN platform for government and law enforcement purposes. The group specializes in iOS malware, notably the KingsPawn strain, which targets mobile devices. Their primary victims have included journalists, political figures, and NGO workers across regions. Carmine Tsunami is known to use domain registrars and inexpensive cloud hosting services for their infrastructure, frequently deploying free Let's Encrypt SSL certificates to mask malicious activities.

Key Capabilities

  • iOS malware development
  • Mobile device exploitation
  • Use of domain registrars and cloud hosting
  • Data exfiltration techniques
  • Spear-phishing campaigns

Software / Tooling

REIGN platform (mobile surveillance tools)
KingsPawn iOS malware

Campaigns & Victims

Carmine Tsunami's operations involve targeting civil society actors in multiple regions. While specific campaigns are not well-documented, the group's focus on mobile device exploitation and surveillance suggests a long-term operational strategy. Their use of domain registrars and cloud hosting indicates careful planning to evade detection.

IOC Patterns

  • Spear-phishing with links to malicious domains
  • Malicious iOS app distribution
  • Use of Let's Encrypt SSL certificates
  • Infrastructure hosted on disposable or low-cost cloud services

Recommended Actions

  • Implement mobile device security monitoring for signs of malware activity.
  • Monitor for suspicious domain registrations and associated network traffic.
  • Enhance email filtering to detect phishing attempts targeting civil society actors.
  • Conduct regular audits of cloud service usage for unauthorized or potentially malicious activities.

Suggested Tags

APT
Mobile Threat
Surveillance Tools
Civil Society Targeting

Confidence Assessment

The data on Carmine Tsunami is limited, making it challenging to comprehensively assess their full capabilities. While the actor's association with QuaDream and their use of iOS malware are well-documented, specific TTPs (tactics, techniques, and procedures) remain unclear. The confidence in the analysis is moderate due to the lack of detailed campaign information.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

164

IOCs

0

Observed Data

0

Tactics

Tags

Data Exfiltration
Government Targeting
APT
Mobile Threat
Surveillance Tools
Civil Society Targeting

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.