Also known as: DEV-0196, QuaDream
Carmine Tsunami is a threat actor linked to an Israel-based private sector offensive actor called QuaDream. QuaDream sells a platform called REIGN to governments for law enforcement purposes, which includes exploits, malware, and infrastructure for data exfiltration from mobile devices. Carmine Tsunami is associated with the iOS malware called KingsPawn and has targeted civil society victims, including journalists, political opposition figures, and NGO workers, in various regions. They utilize domain registrars and inexpensive cloud hosting providers, often using single domains per IP address and deploying free Let's Encrypt SSL certificates.
Executive Summary
Carmine Tsunami (DEV-0196, QuaDream) is a threat actor linked to an Israel-based private sector offensive actor known as Qua Dream. They are associated with the iOS malware KingsPawn and have targeted civil society actors in various regions. Their operations include mobile device exploitation, domain registrar abuse, and use of cloud hosting infrastructure.
Goals & Targeting
Carmine Tsunami appears to target civil society actors, including journalists,政治 opposition figures, and NGO workers, likely with the intent of conducting surveillance or intelligence gathering. Their focus on these sectors suggests a potential interest in monitoring dissidents or activists. The actor's targeting extends across multiple regions, indicating either widespread geographic interests or specific operational objectives.
Enhanced Description
Carmine Tsunami is a cyber threat actor tied to QuaDream, an Israeli private sector entity that develops surveillance tools like the REIGN platform for government and law enforcement purposes. The group specializes in iOS malware, notably the KingsPawn strain, which targets mobile devices. Their primary victims have included journalists, political figures, and NGO workers across regions. Carmine Tsunami is known to use domain registrars and inexpensive cloud hosting services for their infrastructure, frequently deploying free Let's Encrypt SSL certificates to mask malicious activities.
Key Capabilities
Software / Tooling
Campaigns & Victims
Carmine Tsunami's operations involve targeting civil society actors in multiple regions. While specific campaigns are not well-documented, the group's focus on mobile device exploitation and surveillance suggests a long-term operational strategy. Their use of domain registrars and cloud hosting indicates careful planning to evade detection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on Carmine Tsunami is limited, making it challenging to comprehensively assess their full capabilities. While the actor's association with QuaDream and their use of iOS malware are well-documented, specific TTPs (tactics, techniques, and procedures) remain unclear. The confidence in the analysis is moderate due to the lack of detailed campaign information.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
164
IOCs
0
Observed Data
0
Tactics